Application-Layer DDoS Attacks and Defences: A Taxonomy, Comparative Evaluation Framework, and Research Directions

PDF (982KB), PP.300-316

Views: 0 Downloads: 0

Author(s)

Aditya Arsh 1 Priyanka Biswas 2,* Nirmalya Kar 2

1. CDAC Bangalore, Bangalore, Karnataka 560100, India

2. National Institute of Technology Agartala, Agartala, Tripura - 799046, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.04.17

Received: 25 Feb. 2026 / Revised: 25 Mar. 2026 / Accepted: 15 Jul. 2026 / Published: 8 Aug. 2026

Index Terms

DoS attack, DDoS attack, Application Layer, DDoS Defending Techniques, Cloud-Native Security, Zero Trust Architecture

Abstract

Distributed Denial of Service (DDoS) attacks have gained popularity among cybercriminals as a favoured method of disruption. Application layer DDoS attacks are particularly intricate, as they overload web servers with re-quests, rendering them inaccessible to legitimate users and causing availability issues. These attacks are challenging to detect through network and transport-level security measures, making them even more concerning. This paper explores various categories of DDoS attacks, encompassing volumetric and protocol-focused attacks, with a particular focus on application-layer attacks, classifying them into Protocol-specific attacks and Generic attacks. It also delves into diverse defence strategies tailored to combat related attacks, such as HTTP Flood, DHCP starvation, SlowLoris, and others. Unlike earlier surveys, which centre on vulnerability-oriented taxonomies through 2017–2020, this work introduces an explicit, criterion-based comparative evaluation framework for attacks and defences, and extends the taxonomy with post-2020 developments containerized and cloud native low-rate attack surfaces, machine learning-driven detection and adversarial evasion, and zero-trust-based mitigation illustrated with the 2023 HTTP/2 ‘Rapid Reset’ incident. Finding that detection-only mechanisms still dominate current defences, the paper identifies recurring bottlenecks and proposes con-crete future-research directions, including detection resistant to adversarial machine learning and low-rate attack detection in containerized and serverless environments.

Cite This Paper

Aditya Arsh, Priyanka Biswas, Nirmalya Kar, "Application-Layer DDoS Attacks and Defences: A Taxonomy, Comparative Evaluation Framework, and Research Directions", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 300-316, 2026. DOI:10.5815/ijwmt.2026.04.17

Reference

[1]Suriadi Suriadi et al. “Defending web services against denial of service attacks using client puzzles”. In: 2011 IEEE International Conference on Web Services. IEEE. 2011, pp. 25–32. DOI: 10.1109/ICWS.2011.22.
[2]Ryan Farley and Xinyuan Wang. “VoIP shield: A transparent protection of deployed VoIP systems from SIP-based exploits”. In: 2012 IEEE Network Operations and Management Symposium. IEEE. 2012, pp. 486–489. DOI: 10.1109/NOMS.2012.6211937.
[3]Sergey Shekyan. “Are you ready for slow reading?” In: QUALYS BLOG, Available: https://community. qualys. com/blogs/securitylabs/2012/01/05/slow-read (Last access: Dec. 12, 2014) (2012).
[4]Enrico Cambiaso et al. “Slow DoS attacks: definition and categorisation”. In: International Journal of Trust Man-agement in Computing and Communications 1.3-4 (2013), pp. 300–319. DOI: https://doi.org/10.1504/ IJTMCC.2013.056440.
[5]Pawel Chwalinski, Roman Belavkin, and Xiaochun Cheng. “Detection of application layer DDoS attack with clus-tering and likelihood analysis”. In: 2013 IEEE Globecom Workshops (GC Wkshps). IEEE. 2013, pp. 217–222. DOI: 10.1109/GLOCOMW.2013.6824989.
[6]Sujatha Sivabalan and PJ Radcliffe. “A novel framework to detect and block DDoS attack at the application layer”. In: IEEE 2013 Tencon-Spring. IEEE. 2013, pp. 578–582. DOI: 10.1109/TENCONSpring.2013.6584511.
[7]Saman Taghavi Zargar, James Joshi, and David Tipper. “A survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks”. In: IEEE communications surveys & tutorials 15.4 (2013), pp. 2046–2069. DOI: 10.1109/SURV.2013.031413.00127.
[8]Maurizio Aiello et al. “An on-line intrusion detection approach to identify low-rate DoS attacks”. In: 2014 Inter-national Carnahan Conference on Security Technology (ICCST). IEEE. 2014, pp. 1–6. DOI: 10.1109/CCST. 2014.6987039.
[9]Muhammad Ali Akbar and Muddassar Farooq. “Securing SIP-based VoIP infrastructure against flooding attacks and Spam Over IP Telephony”. In: Knowledge and information systems 38.2 (2014), pp. 491–510. DOI: https://doi.org/10.1007/s10115-012-0595-5.
[10]Yuri Gil Dantas, Vivek Nigam, and Iguatemi E Fonseca. “A selective defense for application layer DDoS attacks”. In: 2014 IEEE joint intelligence and security informatics conference. IEEE. 2014, pp. 75–82. DOI: 10.1109/ JISIC.2014.21.
[11]Gulshan Kumar et al. “Understanding denial of service (dos) attacks using osi reference model”. In: International Journal of Education and Science Research 1.5 (2014).
[12]Enrico Cambiaso et al. “Designing and modeling the slow next DoS attack”. In: Computational intelligence in security for information systems conference. Springer. 2015, pp. 249–259. DOI: https : / / doi . org / 10 . 1007/978-3-319-19713-5_22.
[13]Intesab Hussain et al. “A comprehensive study of flooding attack consequences and countermeasures in session initiation protocol (sip)”. In: Security and Communication Networks 8.18 (2015), pp. 4436–4451. DOI: https://doi.org/10.1002/sec.1328.
[14]Georgios Mantas et al. “Application-layer denial of service attacks: taxonomy and survey”. In: International Jour-nal of Information and Computer Security 7.2/3/4 (2015), pp. 216–239. DOI: https://doi.org/10.1504/ IJICS.2015.073028.
[15]Maurizio Mongelli et al. “Detection of DoS attacks through Fourier transform and mutual information”. In: 2015 IEEE International Conference on Communications (ICC). IEEE. 2015, pp. 7204–7209. DOI: 10.1109/ICC. 2015.7249476.
[16]Nikhil Tripathi and Neminath Hubballi. “Exploiting DHCP server-side IP address conflict detection: A DHCP starvation attack”. In: 2015 IEEE International Conference on Advanced Networks and Telecommuncations Systems (ANTS). IEEE. 2015, pp. 1–3. DOI: 10.1109/ANTS.2015.7413661.
[17]Liang Zhu et al. “Connection-oriented DNS to improve privacy and security”. In: 2015 IEEE symposium on security and privacy. IEEE. 2015, pp. 171–186. DOI: 10.1109/SP.2015.18.
[18]Diksha Golait and Neminath Hubballi. “Detecting anomalous behavior in VoIP systems: A discrete event system modeling”. In: IEEE Transactions on Information Forensics and Security 12.3 (2016), pp. 730–745. DOI: 10. 1109/TIFS.2016.2632071.
[19]Vinod Kumar, Krishan Kumar, et al. “Classification of DDoS attack tools and its handling techniques and strat-egy at application layer”. In: 2016 2nd International Conference on Advances in Computing, Communication, & Automation (ICACCA)(Fall). IEEE. 2016, pp. 1–6. DOI: 10.1109/ICACCAF.2016.7749002.
[20]Nikhil Tripathi, Neminath Hubballi, and Yogendra Singh. “How secure are web servers? An empirical study of slow HTTP DoS attacks and detection”. In: 2016 11th International Conference on Availability, Reliability and Security (ARES). IEEE. 2016, pp. 454–463. DOI: 10.1109/ARES.2016.20.
[21]Heng Zhang et al. “Sentry: A novel approach for mitigating application layer DDoS threats”. In: 2016 IEEE Trust-com/BigDataSE/ISPA. IEEE. 2016, pp. 465–472. DOI: 10.1109/TrustCom.2016.0098.
[22]Enrico Cambiaso, Gianluca Papaleo, and Maurizio Aiello. “Slowcomm: Design, development and performance evaluation of a new slow DoS attack”. In: Journal of Information Security and Applications 35 (2017), pp. 23–31. DOI: https://doi.org/10.1016/j.jisa.2017.05.005.
[23]Neminath Hubballi and Nikhil Tripathi. “A closer look into DHCP starvation attack in wireless networks”. In: Computers & Security 65 (2017), pp. 387–404. DOI: https://doi.org/10.1016/j.cose.2016.10.002.
[24]Hossein Hadian Jazi et al. “Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling”. In: Computer Networks 121 (2017), pp. 25–36. DOI: 10.1016/j.comnet.2017.03.018.
[25]Karanpreet Singh, Paramvir Singh, and Krishan Kumar. “Application layer HTTP-GET flood DDoS attacks: Re-search landscape and challenges”. In: Computers & security 65 (2017), pp. 344–372. DOI: https://doi.org/ 10.1016/j.cose.2016.10.005.
[26]Amit Praseed and P Santhi Thilagam. “DDoS attacks at the application layer: Challenges and research perspectives for safeguarding web applications”. In: IEEE Communications Surveys & Tutorials 21.1 (2018), pp. 661–685. DOI: 10.1109/COMST.2018.2870658.
[27]Nikhil Tripathi and Neminath Hubballi. “Slow rate denial of service attacks against HTTP/2 and detection”. In: Computers & security 72 (2018), pp. 255–272. DOI: https://doi.org/10.1016/j.cose.2017.09.009.
[28]Enrico Cambiaso, Giovanni Chiola, and Maurizio Aiello. “Introducing the slowdrop attack”. In: Computer Net-works 150 (2019), pp. 234–249. DOI: 10.1016/j.comnet.2019.01.007.
[29]Shail Saharan and Vishal Gupta. “Prevention and Mitigation of DNS based DDoS attacks in SDN Environment”. In: 2019 11th international conference on communication systems & networks (COMSNETS). IEEE. 2019, pp. 571–573. DOI: 10.1109/COMSNETS.2019.8711258.
[30]Amazon Web Services. AWS Shield Threat Landscape Report – Q1 2020. 2020. URL: https://aws.amazon. com/blogs/security/aws-shield-threat-landscape-report-now-available/ (visited on 06/23/2026).
[31]Felipe S Dantas Silva et al. “A taxonomy of DDoS attack mitigation approaches featured by SDN technologies in IoT scenarios”. In: Sensors 20.11 (2020), p. 3078. DOI: https://doi.org/10.3390/s20113078.
[32]Zhi Li et al. “Exploring New Opportunities to Defeat Low-Rate DDoS Attack in Container-Based Cloud Environ-ment”. In: IEEE Transactions on Parallel and Distributed Systems 31.3 (2020), pp. 695–706. DOI: 10.1109/ TPDS.2019.2942591.
[33]Waleed Nazih et al. “Survey of countering DoS/DDoS attacks on SIP based VoIP networks”. In: Electronics 9.11 (2020), p. 1827. DOI: SurveyofcounteringDoS/DDoSattacksonSIPbasedVoIPnetworks.
[34]Hadeel S Obaid and Esamaddin H Abeed. “DoS and DDoS attacks at OSI layers”. In: International Journal of Multidisciplinary Research and Publications 2.8 (2020), pp. 1–9. ISSN: 2581-6187(Online).
[35]Modupe Odusami et al. A Survey and Meta-Analysis of Application-Layer Distributed Denial-of-Service Attack. 2020. DOI: https://doi.org/10.1002/dac.4603.
[36]Marcin Nawrocki et al. “The far side of DNS amplification: tracing the DDoS attack ecosystem from the internet core”. In: Proceedings of the 21st ACM Internet Measurement Conference. 2021, pp. 419–434. DOI: https://doi.org/10.1145/3487552.3487835.
[37]Nikhil Tripathi and Neminath Hubballi. “Application layer denial-of-service attacks and defense mechanisms: a survey”. In: ACM Computing Surveys (CSUR) 54.4 (2021), pp. 1–33. DOI: https://doi.org/10.1145/ 3448291.
[38]Darragh Leahy and Christina Thorpe. “Zero Trust Container Architecture (ZTCA): A Framework for Applying Zero Trust Principles to Docker Containers”. In: International Conference on Cyber Warfare and Security. Vol. 17. 2022, pp. 111–120.
[39]Naeem Firdous Syed et al. “Zero Trust Architecture (ZTA): A Comprehensive Survey”. In: IEEE Access 10 (2022), pp. 57143–57179. DOI: 10.1109/ACCESS.2022.3174679.
[40]Omer Yoachimik. DDoS attack trends for 2022 Q2. July 6, 2022. URL: https://blog.cloudflare.com/ ddos-attack-trends-for-2022-q2/ (visited on 06/23/2026).
[41]CISA. HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487. 2023. URL: https://www.cisa.gov/news-events / alerts / 2023 / 10 / 10 / http2 - rapid - reset - vulnerability - cve - 2023 - 44487 (visited on 06/23/2026).
[42]Lucas Pardue and Will Desgats. HTTP/2 Rapid Reset: Deconstructing the Record-Breaking Attack. 2023. URL: https : / / blog . cloudflare . com / technical - breakdown - http2 - rapid - reset - ddos - attack/ (visited on 06/23/2026).
[43]Apache Software Foundation. Core Apache HTTP Server Features. Apache HTTP Server Version 2.4 Documenta-tion. Apache Software Foundation. 2026. URL: https://httpd.apache.org/docs/2.4/mod/core. html.
[44]Beloslava Petrova. DNS flood attack explained in details. June 18, 2026. URL: https://www.cloudns.net/ blog/dns-flood-attack-explained-in-details/ (visited on 06/23/2026).