首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >Your Remnant Tells Secret: Residual Resolution in DDoS Protection Services
【24h】

Your Remnant Tells Secret: Residual Resolution in DDoS Protection Services

机译:您的残余物告诉您的秘密:DDoS保护服务中的残留解决方案

获取原文

摘要

The increasing prevalence of Distributed Denial of Service (DDoS) attacks on the Internet has led to the wide adoption of DDoS Protection Service (DPS), which is typically provided by Content Delivery Networks (CDNs) and is integrated with CDN's security extensions. The effectiveness of DPS mainly relies on hiding the IP address of an origin server and rerouting the traffic to the DPS provider's distributed infrastructure, where malicious traffic can be blocked. In this paper, we perform a measurement study on the usage dynamics of DPS customers and reveal a new vulnerability in DPS platforms, called residual resolution, by which a DPS provider may leak origin IP addresses when its customers terminate the service or switch to other platforms, resulting in the failure of protection from future DPS providers as adversaries are able to discover the origin IP addresses and launch the DDoS attack directly to the origin servers. We identify that two major DPS/CDN providers, Cloudflare and Incapsula, are vulnerable to such residual resolution exposure, and we then assess the magnitude of the problem in the wild. Finally, we discuss the root causes of residual resolution and the practical countermeasures to address this security vulnerability.
机译:Internet上分布式拒绝服务(DDoS)攻击的日益流行导致DDoS保护服务(DPS)的广泛采用,该服务通常由内容交付网络(CDN)提供,并与CDN的安全扩展集成在一起。 DPS的有效性主要取决于隐藏原始服务器的IP地址,并将流量重新路由到DPS提供程序的分布式基础结构,从而可以阻止恶意流量。在本文中,我们对DPS客户的使用动态进行了一项测量研究,并揭示了DPS平台中的一个新漏洞,称为剩余分辨率,通过该漏洞,DPS提供商可能会在其客户终止服务或切换到其他平台时泄漏原始IP地址。 ,导致攻击者无法发现原始IP地址并将DDoS攻击直接向原始服务器发起攻击,从而导致无法保护未来的DPS提供者。我们确定了Cloudflare和Incapsula这两个主要的DPS / CDN提供程序很容易受到这种残留分辨率的影响,然后我们评估了野外问题的严重性。最后,我们讨论了残留分辨率的根本原因以及解决此安全漏洞的实际对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号