2021 · Journal of Hardware and Systems Security
The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment
Evidence basis: abstract-and-metadata-reviewed · Review status: catalog-reviewed; paper-author approval pending
anomaly-detection machine-learning resource-analysis performance-analysis
DDoS attacks cloud environment CUSUM bandwidth exhaustion application exhaustion connection exhaustion anomaly detection
Core contribution: The record identifies a cloud-DDoS anomaly-detection study that distinguishes multiple exhaustion-oriented attack types.
Catalog abstract summary
The accessible Springer preview associates the paper with a unified anomaly-detection approach for bandwidth-, application-, and connection-exhaustion DDoS groups, using CUSUM-style change detection and representative HTTP, database/application, and TCP SYN-flood attacks.
Source: Springer two-page preview, paraphrased; complete article not obtained.
Problem and motivation
Cloud DDoS attacks can consume different resource layers and require detection methods that distinguish their behavioral signatures.
Method and contribution
The two-page preview describes one inclusive detector that compares normal and potential-attack traffic/resource behavior across bandwidth, application, and connection exhaustion, with CUSUM for change detection. It mentions representative HTTP, database/application, and TCP SYN-flood classes, but does not expose the complete toolchain, feature set, dataset protocol, or baselines.
Findings and evidence
The preview supports the attack-taxonomy and unified-detection framing, but exposes no sample counts, train/test protocol, hardware, detection rate, false-positive value, or other quantitative result.
Limitations and future directions
Limitations: Only the official two-page Springer preview was accessible; the methods, experiments, references, limitations, and future-work section of the complete article remain unavailable.
Future work: The paper-specific future-work section remains unverified because the complete article was not accessible.
Sources and identifiers
- Published version published
- Springer two-page preview public_preview
When to cite this paper
Cite this paper when its specific method, evidence, or benchmark is directly relevant.
- The paper's method is directly relevant.
- The paper's evidence or benchmark is directly relevant.
Citation
@article{ezzatiJivan2021theuse,
author = {Hossein Abbasi and Naser Ezzati-Jivan and Martine Bellaiche and Chamseddine Talhi and Michel R. Dagenais},
title = {The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment},
year = {2021},
journal = {Journal of Hardware and Systems Security},
volume = {5},
number = {3-4},
pages = {208-222},
publisher = {Springer Science and Business Media LLC},
issn = {2509-3428, 2509-3436},
doi = {10.1007/s41635-021-00119-z},
url = {https://doi.org/10.1007/s41635-021-00119-z}
}Other citation formats for Word and reference managers
Abbasi, H., Ezzati-Jivan, N., Bellaiche, M., Talhi, C., & Dagenais, M. R. (2021). The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment. Journal of Hardware and Systems Security, 5(3-4), 208-222. https://doi.org/10.1007/s41635-021-00119-zH. Abbasi, N. Ezzati-Jivan, M. Bellaiche, C. Talhi, and M. R. Dagenais, "The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment," Journal of Hardware and Systems Security, vol. 5, no. 3-4, pp. 208-222, 2021, doi: 10.1007/s41635-021-00119-z