首页> 外文会议>Applied Cryptography and Network Security >A Pay-per-Use DoS Protection Mechanism for the Web
【24h】

A Pay-per-Use DoS Protection Mechanism for the Web

机译:Web的按使用付费DoS保护机制

获取原文

摘要

Internet service providers have resisted deploying Denial-of-Service (DoS) protection mechanisms despite numerous research results in the area. This is so primarily because ISPs cannot directly charge users for the use of such mechanisms, discouraging investment in the necessary infrastructure and operational support. We describe a pay-per-use system that provides DoS protection for web servers and clients. Our approach is based on WebSOS, an overlay-based architecture that uses reverse Turing tests to discriminate between humans and automated processes that are part of an attack. We extend WebSOS with a credential-based micropayment scheme that combines access control and payment authorization in one operation. Contrary to WebSOS, we use Graphic Turing Tests (GTTs) to prevent malicious code, such as a worm, from using a user's micropayment wallet. Our architecture allows ISPs to accurately charge web clients and servers. Clients can dynamically decide whether to use WebSOS, based on the prevailing network conditions.
机译:尽管该领域有大量研究成果,但互联网服务提供商仍拒绝部署拒绝服务(DoS)保护机制。之所以如此,主要是因为ISP无法直接向用户收取使用此类机制的费用,从而阻碍了对必要基础架构和运营支持的投资。我们描述了按使用付费的系统,该系统为Web服务器和客户端提供DoS保护。我们的方法基于WebSOS,这是一个基于覆盖的体系结构,该体系结构使用反向Turing测试来区分人员和作为攻击一部分的自动化流程。我们通过基于凭证的微支付方案扩展WebSOS,该方案将访问控制和支付授权结合在一个操作中。与WebSOS相反,我们使用图形图灵测试(GTT)来防止诸如蠕虫之类的恶意代码使用用户的小额支付钱包。我们的体系结构允许ISP准确地为Web客户端和服务器收费。客户端可以根据当前的网络状况动态决定是否使用WebSOS。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号