Přístupnostní navigace
E-application
Search Search Close
Doctoral Thesis
Author of thesis: Ing. Marek Sikora, Ph.D.
Acad. year: 2025/2026
Supervisor: doc. Ing. Václav Zeman, Ph.D.
Reviewers: doc. Mgr. Karel Slavíček, Ph.D., Ing. Stanislav Uchytil, Ph.D.
Slow Denial of Service (DoS) attacks (SDAs) represent one of the most sophisticated and elusive forms of application-layer cyber threats, exploiting legitimate protocol mechanisms to exhaust target server resources through low-volume traffic that mimics normal user communication. Despite the growing prevalence of these attacks, publicly available generators for recent SDA vectors are lacking, knowledge of the vulnerability of widely deployed servers is insufficient, and effective detection methods for attacks that closely resemble legitimate traffic have not yet been published. This dissertation proposes a comprehensive research framework encompassing the modeling, experimental verification, and detection of SDAs. Formal communication models of eleven attack vectors were proposed - spanning classical attacks (Slowloris, Slow POST, Slow Read), application-independent attacks (Slowcomm, Slow Next, SlowDrop), and Hypertext Transfer Protocol version 2 (HTTP/2)-specific attacks (Slow Headers, Slow POST, Slow Read, Slow Settings, Slow Preface). These models were implemented in a novel universal SDA generator - the first publicly described tool to cover all of these attack types within a single framework. Using this generator, a comprehensive vulnerability assessment was conducted on seven server instances (Apache, Nginx, lighttpd, Internet Information Services (IIS), vsftpd, OpenSSH) across the HTTP, File Transfer Protocol (FTP), and Secure Shell (SSH) protocols. Novel detection signatures were proposed and experimentally verified for ten SDA vectors within an intrusion prevention system. For attacks resistant to signature-based detection, particularly SlowDrop and Slow Next, a machine-learning-based anomaly detection method using a Random Forest classifier was proposed and evaluated, identifying the FIN Flag Count as the key discriminative flow-level feature. The findings revealed significant differences in server resilience to SDAs, confirmed the effectiveness of the proposed signature-based detection for attacks with well-defined communication patterns, and validated the feasibility of a machine-learning-based approach for traffic-mimicking attacks. The dissertation proposes a layered defense strategy combining both detection paradigms.
low DoS attacks, denial of service, application layer, attack modeling, network attack detection, signature-based detection, machine learning, Random Forest, web server vulnerability, HTTP/2, SlowDrop, Slowcomm, Slow Next, intrusion prevention system }
Date of defence
19.05.2026
Result of the defence
Defended (thesis was successfully defended)
Process of defence
Disertant jasně a stručně objasnil vědecké výsledky své práce. Zodpověděl všechny otázky členů komise a oponentů.
Language of thesis
English
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Teleinformatics (DKC-TLI)
Composition of Committee
prof. Ing. Zdeněk Smékal, CSc. (předseda) doc. Ing. František Urban, CSc. (člen) doc. Ing. Martin Kyselák, Ph.D. (člen) doc. Ing. Otto Dostál, CSc. (člen) doc. Ing. Zdeněk Martinásek, Ph.D. (člen) doc. Ing. Lukáš Malina, Ph.D. (člen) doc. Mgr. Karel Slavíček, Ph.D. (člen) Ing. Stanislav Uchytil, Ph.D. (člen)
Supervisor’s reportdoc. Ing. Václav Zeman, Ph.D.
Reviewer’s reportdoc. Mgr. Karel Slavíček, Ph.D.
Reviewer’s reportIng. Stanislav Uchytil, Ph.D.
Responsibility: Mgr. et Mgr. Hana Odstrčilová