Session

A Taxonomy-Driven Detection and Mitigation Framework for Volumetric, Protocol, and Application-Layer

Cloud-native systems—from Azure Kubernetes Service to Sitecore XM Cloud’s headless architecture—are increasingly vulnerable to multi-vector DDoS attacks designed specifically to exploit resource elastic scaling, API gateways, microservices, and CDN-based delivery. Modern botnets now employ AI-based traffic shaping, rotating behavioral patterns, DNS water-torture attacks, HTTP/2 rapid reset attacks, and protocol abuse that bypass traditional rate limiting and WAFs.

This session provides a deep technical exploration of DDoS attacks in cloud environments, building upon the research taxonomy defined in DDoS Attacks in Cloud Computing: Issues, Taxonomy, and Future Research Directions, and extends it with new AI-driven detection patterns.

The session will cover:

1. Advanced Distributed Attacks in Cloud Computing

Volumetric floods (UDP amplification, SSDP/CLDAP, Memcached)

Protocol-level attacks (SYN/ACK floods, TCP exhaustion, HTTP/2 rapid reset)

Application-layer attacks (GraphQL/API flooding, slowloris variants, token exhaustion)

Botnet evolution: AI-driven request shaping and mimicked user behaviour

Attacks specifically targeting Autoscaling and Serverless consumption models

2. Cloud-Specific DDoS Issues

Exploitation of auto-scaling (cost exhaustion attacks)

API gateway crashes via malformed payload bursts

CDN caching bypass techniques

Microservice overload cascades

Saturation of headless rendering hosts (Next.js/Node servers in Sitecore XM Cloud)

“Stealth” L7 attacks that stay under WAF thresholds

Cloud-to-cloud bot propagation

3. Formal Taxonomy for Classification & Detection

Following the research paper taxonomy:

Attack vector classification (Volumetric, Protocol, Application)

Targeting classification (Infrastructure, Platform, Application)

Behavioural signature extraction

Botnet orchestration mapping

Resource consumption propagation models

4. AI-Enhanced Detection & Mitigation Pipeline

A full enterprise-ready architecture using:

Azure Front Door adaptive throttling

API Management anomaly detection

Azure Sentinel + UEBA for behavioural correlation

ML-trained anomaly detection using:

Flow-based features

Entropy of request headers

Inter-arrival timing patterns

Connection churn rate patterns

Time-series analysis using LSTM and Prophet models

Real-time traffic fingerprinting

Automatic IP reputation scoring using federated threat intel

Mitigation orchestration using Logic Apps and Azure Functions

Attendees will leave with a practical, cloud-centered, taxonomy-driven blueprint for building a resilient DDoS architecture in enterprise environments.

Darlington Okeke

Cybersecurity Researcher | CEH | CPT | MSc Cyber Security | AI for Threat Detection

Cheltenham, United Kingdom

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top