VLDB 2026 Research / reviewers in the wild / expert
Anmol Kumar 0001
dblp:170/5818-1
· DBLP profile ↗
5ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0003-2331-1066ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Microservice Assisted Multi-Level DDoS Defense Mechanism in Containerized Cloud EnvironmentsabstractCloud computing revolutionized the delivery of IT services by providing unparalleled scalability, flexibility, and cost savings. The expansion of cloud computing also attracts Distributed Denial of Service (DDoS) attackers, causing them to shift their targets from traditional server systems to cloud infrastructure. DDoS attacks bombard systems with malicious traffic, creating a significant threat to the availability of cloud services. In the state-of-the-art solutions, we found that resource isolation for legitimate users plays a crucial role in maintaining the service availability under DDoS attacks. By isolating resources, target services are able to maintain their functionality for legitimate users without experiencing substantial interruption, even in the presence of a DDoS attack. In this work, we proposed a robust defense system against DDoS attacks that employs three strategies: categorizing incoming requests based on the frequency of their submissions to different services, allocating resources for distinct services, and implementing a microservice architecture within a cloud infrastructure based on containers. The incoming requests are categorized into four distinct categories: red, orange, yellow, and green. Each category was determined by the number of requests made for a specific service in comparison to threshold values. Subsequently, the requests were served in separate containers. To implement microservice architecture, we deploy each web service on distinct containers. This implies that requests from various users for distinct services get served in separate containers. We tested this approach in three distinct scenarios (E1, E2, and E3) by varying the number of web services at the target infrastructure (2 services on E1, 3 services on E2, and 5 services on E3). By this, we test the scalability of the proposed defense system in the presence of DDoS attacks. The experimental results show that the proposed defense system is highly effective, maintaining service availability up to 90% even under DDoS attacks. This result demonstrates the system's ability to keep services running smoothly for legitimate users, even in the presence of DDoS attacks. Anmol Kumar 0001, Shitharth Selvarajan, Mayank Agarwal |
IEEE Trans. Cloud Comput. | 1 |
| 2025 | Reducing Internal Collateral Damage From DDoS Attacks Through Micro-Service Cloud ArchitectureabstractMitigating DDoS attacks poses a significant challenge for cyber security teams within victim organizations, as these attacks directly target service availability. Most DDoS mitigation solutions focus address the direct effects of DDoS attacks, such as service unavailability and network congestion, while the indirect effects, including collateral damage to legitimate users, receive substantially less attention in the present state-of-the-art. To address this gap, we propose a novel defense architecture designed to mitigate collateral damage and ensure service availability for legitimate users even under attack conditions. The proposed approach employs containerization, micro-services architecture, and traffic segmentation to enhance system resilience and fortify security. We send requests for two distinct services, namely an HTTP-based service and an SSH service, in order to analyze the collateral damage caused by the DDoS attack. The proposed architecture classifies incoming HTTP traffic into two categories: “benign traffic” and “suspicious traffic,” determined by the number of requests originating from the same source address. We tested this approach in three different scenarios (S-1, S-2, and S-3). Experimental results demonstrate that the proposed architecture effectively isolates suspicious traffic, mitigating its impact on benign services. This ensures the availability of critical services during a DDoS attack while minimizing collateral damage. In scenarios S-1, S-2, and S-3, it maintains service availability at 3%, 67%, and 98%, respectively, highlighting its efficacy in the face of varying levels of DDoS attack intensity. Furthermore, the architecture is extremely effective in reducing the collateral effects on SSH requests during a DDoS attack. In the S-1 scenario, SSH login time was reduced by 25%, 46%, and 27%, respectively. In the S-2 scenario, the reductions were 99%, 53%, and 29%. In the same vein, the system achieved reductions of 4%, 17%, and 99% in the S-3 scenario. Anmol Kumar 0001, Mayank Agarwal |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Quick service during DDoS attacks in the container-based cloud environment
Anmol Kumar 0001, Mayank Agarwal |
J. Netw. Comput. Appl. | 1 |
| 2023 | Preserving Service Availability Under DDoS Attack in Micro-Service Based Cloud InfrastructureabstractDistributed denial of service (DDoS) attacks target the availability of the victim's services. DDoS attacks, being resource-consumption attacks, create heavy resource contention. In the state of the art, we found that resource isolation for legitimate users assisted in maintaining service availability even in the presence of DDoS attacks. As the networks are moving towards micro-service architecture, DDoS attack on these architecture can lead to disruption of services. In this work, we implement a micro-service architecture using container based environment. We use the threshold connection and micro-service architecture to preserve service availability under DDoS attack. The threshold connection will check for the active connection of distinct web pages, and micro-service architecture helps in serving those different requests on different containers. We classify those users whose number of requests is greater than the threshold connection as attacker and the rest of them as benign users. Also, we classify the target web page into two categories: high resource consumption web pages and low resource consumption web pages based on their resource consumption. We serve the requests for both pages in different containers. Our experimental results show that even in the presence of a massive DDoS attack, our proposed mechanism is able to preserve the availability of the target service. The proposed methodology leads to failure of only 8 benign requests as compared to 499 under state-of-the-art. It is imperative to emphasize that the proposed technique should not be regarded as a DDoS detection instrument but rather as a supplementary component to an existing detection solutions. Anmol Kumar 0001, Mayank Agarwal |
SIN | 1 |
| 2023 | Service separation assisted DDoS attack mitigation in cloud targets
Anmol Kumar 0001, Gaurav Somani 0001 |
J. Inf. Secur. Appl. | 1 |