NORMA eResearch @NCI Library

Mitigating Bot Threats in E-Commerce through Behaviour Based Rate Limiting

Mundolli Kalam, Sivadas (2025) Mitigating Bot Threats in E-Commerce through Behaviour Based Rate Limiting. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (597kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (453kB) | Preview

Abstract

The increasing popularity of automated bot-attacks and high levels of API traffic are posing severe problems to the security and stability of the current e-commerce systems. The traditional statical rate-limiting methods tend to be weak in relation to dynamic traffic and patterns, causing services to run poorly, API abuse, and denial-of-service attacks. This study introduces a framework of rate-limiting based on adaptive rate-limiting implemented on FastAPI, Redis, and Lua scripting to offer real-time, behaviour-driven API traffic control. The system is designed to dynamically modify request thresholds when there is live traffic anomaly to respond better to legitimate and malicious users.

Prometheus and Grafana (advanced visualization) are incorporated into the architecture, which allows taking an overview of the actions of the HTTP responses, IP behaviours, latency, and block rates. AWS was tested and evaluated, and simulated attacks were produced using Shell script to test on high load. Findings show that the adaptive mechanism is more effective than the traditional rate limiting where 98 percentage of bot traffic is avoided and the latency of legitimate clients is low. The model justifies the feasibility and effectiveness of Redis-Lua atomics execution and real-time monitoring as a scalable and robust defence model of API-based infrastructures. The research paper will also make a contribution to the academic literature on the cloud API security domain by offering an end to end, production ready solution that meets the present industry demands.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Prior, Michael
UNSPECIFIED
Uncontrolled Keywords: Adaptive Rate Limiting; Redis Lua Scripting; FastAPI; Prometheus; Grafana; Bot Mitigation; E-Commerce Security; Anomaly Detection; Traffic Monitoring
Subjects: Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
H Social Sciences > HF Commerce > Electronic Commerce
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 03 Sep 2026 11:51
Last Modified: 03 Sep 2026 11:51
URI: https://norma.ncirl.ie/id/eprint/9809

Actions (login required)

View Item View Item