EDBT 2026 Demo / reviewers in the wild / expert
Amit Praseed
dblp:213/1951
· DBLP profile ↗
6ranked-venue papers
5as first author
4since 2021 · last 2023
0000-0003-3965-0118ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Hindi fake news detection using transformer ensembles
Amit Praseed, Jelwin Rodrigues, P. Santhi Thilagam |
Eng. Appl. Artif. Intell. | 1 |
| 2022 | HTTP request pattern based signatures for early application layer DDoS detection: A firewall agnostic approach
Amit Praseed, P. Santhi Thilagam |
J. Inf. Secur. Appl. | 1 |
| 2021 | Fuzzy Request Set Modelling for Detecting Multiplexed Asymmetric DDoS Attacks on HTTP/2 servers
Amit Praseed, P. Santhi Thilagam |
Expert Syst. Appl. | 1 |
| 2021 | Modelling Behavioural Dynamics for Asymmetric Application Layer DDoS DetectionabstractAsymmetric application layer DDoS attacks using computationally intensive HTTP requests are an extremely dangerous class of attacks capable of taking down web servers with relatively few attacking connections. These attacks consume limited network bandwidth and are similar to legitimate traffic, which makes their detection difficult. Existing detection mechanisms for these attacks use indirect representations of actual user behaviour and complex modelling techniques, which leads to a higher false positive rate (FPR) and longer detection time, which makes them unsuitable for real time use. There is a need for simple, efficient and adaptable detection mechanisms for asymmetric DDoS attacks. In this work, an attempt is made to model the actual behavioural dynamics of legitimate users using a simple annotated Probabilistic Timed Automata (PTA) along with a suspicion scoring mechanism for differentiating between legitimate and malicious users. This allows the detection mechanism to be extremely fast and have a low FPR. In addition, the model can incrementally learn from run-time traces, which makes it adaptable and reduces the FPR further. Experiments on public datasets reveal that our proposed approach has a high detection rate and low FPR and adds negligible overhead to the web server, which makes it ideal for real time use. Amit Praseed, P. Santhi Thilagam |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Multiplexed Asymmetric Attacks: Next-Generation DDoS on HTTP/2 ServersabstractDistributed Denial of Service (DDoS) attacks using the HTTP protocol have started gaining popularity in recent years. A recent trend in this direction has been the use of computationally expensive requests to launch attacks. These attacks, called Asymmetric Workload attacks can bring down servers using limited resources, and are extremely difficult to detect. The introduction of HTTP/2 has been welcomed by developers because it improves user experience and efficiency. This was made possible by the ability to transport HTTP requests and their associated inline resources simultaneously by using Multiplexing and Server Push. However multiplexing has made request traffic bursty and rendered DDoS detection mechanisms based on connection limiting obsolete. Contrary to its intention, multiplexing can also be misused to launch sophisticated DDoS attacks using multiple high workload requests in a single TCP connection. However, sufficient research has not been done in this area. Existing research demonstrates that the HTTP/2 protocol allows users to launch DDoS attacks easily, but does not focus on whether an HTTP/2 server can handle DDoS attacks more efficiently or not. Also, sufficient research has not been done on the possibility of Multiplexing and Server Push being misused. In this work, we analyse the performance of an HTTP/2 server compared to an HTTP/1.1 server under an Asymmetric DDoS attack for the same load. We propose a new DDoS attack vector called a Multiplexed Asymmetric DDoS attack, which uses multiplexing in a different way than intended. We show that such an attack can bring down a server with just a few attacking clients. We also show that a Multiplexed Asymmetric Attack on a server with Server Push enabled can trigger an egress network layer flood in addition to an application layer attack. Amit Praseed, P. Santhi Thilagam |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | DetLogic: A black-box approach for detecting logic vulnerabilities in web applications
G. Deepa, P. Santhi Thilagam, Amit Praseed, Alwyn Roshan Pais |
J. Netw. Comput. Appl. | 3 |