Aditya Arsh

Work place: CDAC Bangalore, Bangalore, Karnataka 560100, India

E-mail: aditya.arsh4417@gmail.com

Website: https://orcid.org/0009-0009-3234-0927

Research Interests:

Biography

Aditya Arsh is a Project Engineer at CDAC Bangalore, engaged in cyber security research and development initiatives. His areas of work include DNS security, domain name and infrastructure analysis, malware analysis, vulnerability assessment and penetration testing (VAPT), and threat detection and analysis. He holds a bachelor’s degree in computer science and engineering from BIT Mesra and a Master of Technology (M. Tech) degree in Cyber Security from NIT Agartala. His interests lie in applied cyber security research, detection of malicious online activity, and strengthening defensive security mechanisms.

Author Articles
Application-Layer DDoS Attacks and Defences: A Taxonomy, Comparative Evaluation Framework, and Research Directions

By Aditya Arsh Priyanka Biswas Nirmalya Kar

DOI: https://doi.org/10.5815/ijwmt.2026.04.17, Pub. Date: 8 Aug. 2026

Distributed Denial of Service (DDoS) attacks have gained popularity among cybercriminals as a favoured method of disruption. Application layer DDoS attacks are particularly intricate, as they overload web servers with re-quests, rendering them inaccessible to legitimate users and causing availability issues. These attacks are challenging to detect through network and transport-level security measures, making them even more concerning. This paper explores various categories of DDoS attacks, encompassing volumetric and protocol-focused attacks, with a particular focus on application-layer attacks, classifying them into Protocol-specific attacks and Generic attacks. It also delves into diverse defence strategies tailored to combat related attacks, such as HTTP Flood, DHCP starvation, SlowLoris, and others. Unlike earlier surveys, which centre on vulnerability-oriented taxonomies through 2017–2020, this work introduces an explicit, criterion-based comparative evaluation framework for attacks and defences, and extends the taxonomy with post-2020 developments containerized and cloud native low-rate attack surfaces, machine learning-driven detection and adversarial evasion, and zero-trust-based mitigation illustrated with the 2023 HTTP/2 ‘Rapid Reset’ incident. Finding that detection-only mechanisms still dominate current defences, the paper identifies recurring bottlenecks and proposes con-crete future-research directions, including detection resistant to adversarial machine learning and low-rate attack detection in containerized and serverless environments.

[...] Read more.
Other Articles