{
  "schema_version": "0.6.0",
  "paper_id": "anomaly-detection-ddos-attacks-cloud-environment",
  "page_url": "https://naser.github.io/research-publications/papers/anomaly-detection-ddos-attacks-cloud-environment/",
  "title": "The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment",
  "title_variants": [],
  "authors": [
    "Hossein Abbasi",
    "Naser Ezzati-Jivan",
    "Martine Bellaiche",
    "Chamseddine Talhi",
    "Michel R. Dagenais"
  ],
  "author_details": [
    {
      "name": "Hossein Abbasi",
      "orcid": "https://orcid.org/0000-0002-4024-4355",
      "profile_url": "https://dblp.org/pid/241/6443.html"
    },
    {
      "name": "Naser Ezzati-Jivan",
      "orcid": "https://orcid.org/0000-0003-1435-6297",
      "profile_url": "https://naser.github.io/"
    },
    {
      "name": "Martine Bellaiche",
      "orcid": null,
      "profile_url": "https://dblp.org/pid/06/7909.html"
    },
    {
      "name": "Chamseddine Talhi",
      "orcid": null,
      "profile_url": "https://dblp.org/pid/63/6619.html"
    },
    {
      "name": "Michel R. Dagenais",
      "orcid": null,
      "profile_url": "https://dblp.org/pid/60/309.html"
    }
  ],
  "publication": {
    "year": 2021,
    "venue": "Journal of Hardware and Systems Security",
    "type": "journal article",
    "publication_date": "2021-10-16",
    "online_date": "2021-10-16",
    "print_date": "2021-12",
    "volume": "5",
    "issue": "3-4",
    "pages": "208-222",
    "article_number": null,
    "publisher": "Springer Science and Business Media LLC",
    "issn": [
      "2509-3428",
      "2509-3436"
    ],
    "isbn": [],
    "crossref_type": "journal-article"
  },
  "publication_type": "journal article",
  "status": "published_with_public_preview",
  "canonical_source_url": "https://doi.org/10.1007/s41635-021-00119-z",
  "source_record_id": "the-use-of-anomaly-detection-for-the-detection-of-different-types-of-ddos-attacks-in-cloud-envir-ba1d631919",
  "identifiers": {
    "doi": "10.1007/s41635-021-00119-z"
  },
  "abstract": "The accessible Springer preview associates the paper with a unified anomaly-detection approach for bandwidth-, application-, and connection-exhaustion DDoS groups, using CUSUM-style change detection and representative HTTP, database/application, and TCP SYN-flood attacks.",
  "abstract_source": "Springer two-page preview, paraphrased; complete article not obtained.",
  "abstract_available": true,
  "scholar_eligibility": {
    "eligible": false,
    "basis": "not-eligible",
    "note": "The page is a discovery record; it does not claim Google Scholar article-host eligibility."
  },
  "description": "The accessible Springer preview associates the paper with a unified anomaly-detection approach for bandwidth-, application-, and connection-exhaustion DDoS groups, using CUSUM-style change detection and representative HTTP, database/application, and TCP SYN-flood attacks.",
  "evidence_level": "metadata-or-abstract-reviewed",
  "evidence": {
    "source_basis": "abstract-and-metadata-reviewed",
    "coverage": "abstract and bibliographic metadata",
    "summary_origin": "AI-assisted catalog editorial summary",
    "review_status": "catalog-reviewed; paper-author approval pending",
    "verified_on": "2026-08-09",
    "sources": [
      {
        "note": "DOI: https://doi.org/10.1007/s41635-021-00119-z"
      },
      {
        "note": "DBLP record: https://dblp.org/rec/journals/jhss/AbbasiJBTD21"
      },
      {
        "note": "Official Springer preview read privately; SHA-256 912bc86c865ca297eaae75b03c8b6781369d504cb6eeb078bef2f138fce6db60; private evidence report: reports/agent-batch-04.md"
      }
    ]
  },
  "summary": {
    "core_contribution": "The record identifies a cloud-DDoS anomaly-detection study that distinguishes multiple exhaustion-oriented attack types.",
    "problem": "Cloud DDoS attacks can consume different resource layers and require detection methods that distinguish their behavioral signatures.",
    "method": "The two-page preview describes one inclusive detector that compares normal and potential-attack traffic/resource behavior across bandwidth, application, and connection exhaustion, with CUSUM for change detection. It mentions representative HTTP, database/application, and TCP SYN-flood classes, but does not expose the complete toolchain, feature set, dataset protocol, or baselines.",
    "findings": "The preview supports the attack-taxonomy and unified-detection framing, but exposes no sample counts, train/test protocol, hardware, detection rate, false-positive value, or other quantitative result.",
    "limitations": "Only the official two-page Springer preview was accessible; the methods, experiments, references, limitations, and future-work section of the complete article remain unavailable.",
    "future_work": "The paper-specific future-work section remains unverified because the complete article was not accessible."
  },
  "tags": [
    "anomaly-detection",
    "machine-learning",
    "resource-analysis",
    "performance-analysis"
  ],
  "keywords": [
    "DDoS attacks",
    "cloud environment",
    "CUSUM",
    "bandwidth exhaustion",
    "application exhaustion",
    "connection exhaustion",
    "anomaly detection"
  ],
  "versions": [
    {
      "id": "published-version",
      "label": "Published version",
      "relation": "version-of-record",
      "title": "The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment",
      "url": "https://doi.org/10.1007/s41635-021-00119-z",
      "pdf_url": null,
      "status": "published",
      "canonical_for_citation": true
    },
    {
      "id": "springer-two-page-preview",
      "label": "Springer two-page preview",
      "relation": "source-record",
      "title": "The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment",
      "url": "https://page-one.springer.com/pdf/preview/10.1007/s41635-021-00119-z",
      "pdf_url": null,
      "status": "public_preview",
      "canonical_for_citation": false
    }
  ],
  "access": {
    "status": "published_with_public_preview",
    "note": "The DOI and article identity are verified, but the authorized public Springer route exposed only a two-page preview rather than the complete article. The preview identifies bandwidth-, application-, and connection-exhaustion groups, CUSUM, and representative attack classes; no full-paper metric is asserted.",
    "license": null
  },
  "resources": {
    "code": null,
    "data": null,
    "slides": null,
    "demo": null
  },
  "citation_guidance": {
    "when_to_cite": "Cite this paper when its specific method, evidence, or benchmark is directly relevant.",
    "points": [
      "The paper's method is directly relevant.",
      "The paper's evidence or benchmark is directly relevant."
    ],
    "canonical_version_id": "published-version"
  },
  "provenance": {
    "metadata_verified_on": "2026-08-09",
    "metadata_source": [
      "DOI: https://doi.org/10.1007/s41635-021-00119-z",
      "DBLP record: https://dblp.org/rec/journals/jhss/AbbasiJBTD21",
      "Official Springer preview read privately; SHA-256 912bc86c865ca297eaae75b03c8b6781369d504cb6eeb078bef2f138fce6db60; private evidence report: reports/agent-batch-04.md"
    ],
    "summary_written_by": "AI-assisted",
    "summary_verified_by": "metadata/abstract-grounded catalog review; full-text review and author approval pending",
    "linked_preprint_record": null,
    "author_order_note": null
  },
  "batch": {
    "phase": 2,
    "batch_label": "expanded forty-paper release",
    "status": "included_in_expanded_catalog",
    "selected_at": "2026-08-09"
  }
}
