首页> 外文OA文献 >WebSOS: An Overlay-based System For Protecting Web Servers From Denial of Service Attacks
【2h】

WebSOS: An Overlay-based System For Protecting Web Servers From Denial of Service Attacks

机译:WebSOS:一种基于覆盖的系统,用于保护Web服务器免受拒绝服务攻击

摘要

We present WebSOS, a novel overlay-based architecture that provides guaranteed access to a web server that is targeted by a denial of service (DoS) attack. Our approach exploits two key characteristics of the web environment: its design around a human–centric interface, and the extensibility inherent in many browsers through downloadable "applets." We guarantee access to a web server for a large number of previously unknown users, without requiring pre-existing trust relationships between users and the system, by using reverse Graphic Turing Tests. Furthermore, our system makes it easy for service providers to charge users, providing incentives to a commercial offering of the service. Users can dynamically decide whether to use the WebSOS overlay, based on the prevailing network conditions. Our prototype requires no modifications to either servers or browsers, and makes use of Graphical Turing Tests, web proxies, and client authentication using the SSL/TLS protocol, all readily supported by modern browsers. We then extend this system with a credential-based micropayment scheme that combines access control and payment authorization in one operation. Turing tests ensure that malicious code, such as a worm, cannot abuse a user's micropayment wallet. We use the WebSOS prototype to conduct a performance evaluation over the Internet using PlanetLab, a testbed for experimentation with network overlays. We determine the end-to-end latency using both a chord-based approach and our shortcut extension. Our evaluation shows the latency increase by a factor of 7 and 2 respectively, confirming our simulation results.
机译:我们介绍WebSOS,这是一种新颖的基于覆盖的体系结构,可提供对拒绝服务(DoS)攻击目标的Web服务器的有保证的访问。我们的方法利用了Web环境的两个关键特征:围绕人为中心的界面设计,以及许多浏览器通过可下载的“小程序”固有的可扩展性。通过使用反向图形Turing测试,我们保证大量以前未知的用户可以访问Web服务器,而无需用户和系统之间预先存在的信任关系。此外,我们的系统使服务提供商可以轻松地向用户收费,从而为服务的商业化提供了激励。用户可以根据当前的网络状况动态决定是否使用WebSOS覆盖。我们的原型不需要对服务器或浏览器进行任何修改,并且使用了图形化图灵测试,Web代理和使用SSL / TLS协议的客户端身份验证,所有这些都易于获得现代浏览器的支持。然后,我们通过基于凭证的微支付方案扩展该系统,该方案将访问控制和支付授权结合在一个操作中。图灵测试可确保蠕虫等恶意代码不会滥用用户的小额支付钱包。我们使用WebSOS原型通过PlanetLab在Internet上进行性能评估,PlanetLab是用于测试网络覆盖的测试平台。我们使用基于和弦的方法和快捷方式扩展来确定端到端延迟。我们的评估显示等待时间分别增加了7倍和2倍,证实了我们的仿真结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号