Nirmalya Kar

Work place: National Institute of Technology Agartala, Agartala, Tripura - 799046, India

E-mail: nirmalya@ieee.org

Website: https://orcid.org/0000-0002-7371-232X

Research Interests:

Biography

Nirmalya Kar is an Assistant Professor in the Department of Computer Science and Engineering at the National Institute of Technology (NIT) Agartala. He also serves as the Chief Information Security Officer at the Institution. Having more than 18 years of teaching and research experience, Dr. Kar specializes in Information Security, Cryptography, Computational Intelligence and the Internet of Things (IoT). He has more than 50+ research contributions in referred journals, book chapters and conference proceedings and has been involved in various academic and administrative roles, including organising chair and general chair of International Conferences, overseeing campus-wide networking and coordinating high-performance computing initiatives at NIT Agartala.

Author Articles
Application-Layer DDoS Attacks and Defences: A Taxonomy, Comparative Evaluation Framework, and Research Directions

By Aditya Arsh Priyanka Biswas Nirmalya Kar

DOI: https://doi.org/10.5815/ijwmt.2026.04.17, Pub. Date: 8 Aug. 2026

Distributed Denial of Service (DDoS) attacks have gained popularity among cybercriminals as a favoured method of disruption. Application layer DDoS attacks are particularly intricate, as they overload web servers with re-quests, rendering them inaccessible to legitimate users and causing availability issues. These attacks are challenging to detect through network and transport-level security measures, making them even more concerning. This paper explores various categories of DDoS attacks, encompassing volumetric and protocol-focused attacks, with a particular focus on application-layer attacks, classifying them into Protocol-specific attacks and Generic attacks. It also delves into diverse defence strategies tailored to combat related attacks, such as HTTP Flood, DHCP starvation, SlowLoris, and others. Unlike earlier surveys, which centre on vulnerability-oriented taxonomies through 2017–2020, this work introduces an explicit, criterion-based comparative evaluation framework for attacks and defences, and extends the taxonomy with post-2020 developments containerized and cloud native low-rate attack surfaces, machine learning-driven detection and adversarial evasion, and zero-trust-based mitigation illustrated with the 2023 HTTP/2 ‘Rapid Reset’ incident. Finding that detection-only mechanisms still dominate current defences, the paper identifies recurring bottlenecks and proposes con-crete future-research directions, including detection resistant to adversarial machine learning and low-rate attack detection in containerized and serverless environments.

[...] Read more.
Other Articles