Session
A Taxonomy-Driven Detection and Mitigation Framework for Volumetric, Protocol, and Application-Layer
Cloud-native systems—from Azure Kubernetes Service to Sitecore XM Cloud’s headless architecture—are increasingly vulnerable to multi-vector DDoS attacks designed specifically to exploit resource elastic scaling, API gateways, microservices, and CDN-based delivery. Modern botnets now employ AI-based traffic shaping, rotating behavioral patterns, DNS water-torture attacks, HTTP/2 rapid reset attacks, and protocol abuse that bypass traditional rate limiting and WAFs.
This session provides a deep technical exploration of DDoS attacks in cloud environments, building upon the research taxonomy defined in DDoS Attacks in Cloud Computing: Issues, Taxonomy, and Future Research Directions, and extends it with new AI-driven detection patterns.
The session will cover:
1. Advanced Distributed Attacks in Cloud Computing
Volumetric floods (UDP amplification, SSDP/CLDAP, Memcached)
Protocol-level attacks (SYN/ACK floods, TCP exhaustion, HTTP/2 rapid reset)
Application-layer attacks (GraphQL/API flooding, slowloris variants, token exhaustion)
Botnet evolution: AI-driven request shaping and mimicked user behaviour
Attacks specifically targeting Autoscaling and Serverless consumption models
2. Cloud-Specific DDoS Issues
Exploitation of auto-scaling (cost exhaustion attacks)
API gateway crashes via malformed payload bursts
CDN caching bypass techniques
Microservice overload cascades
Saturation of headless rendering hosts (Next.js/Node servers in Sitecore XM Cloud)
“Stealth” L7 attacks that stay under WAF thresholds
Cloud-to-cloud bot propagation
3. Formal Taxonomy for Classification & Detection
Following the research paper taxonomy:
Attack vector classification (Volumetric, Protocol, Application)
Targeting classification (Infrastructure, Platform, Application)
Behavioural signature extraction
Botnet orchestration mapping
Resource consumption propagation models
4. AI-Enhanced Detection & Mitigation Pipeline
A full enterprise-ready architecture using:
Azure Front Door adaptive throttling
API Management anomaly detection
Azure Sentinel + UEBA for behavioural correlation
ML-trained anomaly detection using:
Flow-based features
Entropy of request headers
Inter-arrival timing patterns
Connection churn rate patterns
Time-series analysis using LSTM and Prophet models
Real-time traffic fingerprinting
Automatic IP reputation scoring using federated threat intel
Mitigation orchestration using Logic Apps and Azure Functions
Attendees will leave with a practical, cloud-centered, taxonomy-driven blueprint for building a resilient DDoS architecture in enterprise environments.
Darlington Okeke
Cybersecurity Researcher | CEH | CPT | MSc Cyber Security | AI for Threat Detection
Cheltenham, United Kingdom
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top