English

Mitigation of Random Query String DoS via Gossip

Cryptography and Security 2012-02-24 v2

Abstract

This paper presents a mitigation scheme to cope with the random query string Denial of Service (DoS) attack, which is based on a vulnerability of current Content Delivery Networks (CDNs). The attack exploits the fact that edge servers composing a CDN, receiving an HTTP request for a resource with an appended random query string never saw before, ask the origin server for a (novel) copy of the resource. Such characteristics can be employed to take an attack against the origin server by exploiting edge servers. Our strategy adopts a simple gossip protocol executed by edge servers to detect the attack. Based on such a detection, countermeasures can be taken to protect the origin server and the CDN against the attack. We provide simulation results that show the viability of our approach.

Keywords

Cite

@article{arxiv.1109.4404,
  title  = {Mitigation of Random Query String DoS via Gossip},
  author = {Stefano Ferretti and Vittorio Ghini},
  journal= {arXiv preprint arXiv:1109.4404},
  year   = {2012}
}

Comments

a revised version will appear in Proc. of the 6th International Conference on Information Systems, Technology and Management (ICISTM-2012), Grenoble, France, Springer Series in Communications in Computer and Information Science (CCIS), March 2012

R2 v1 2026-06-21T19:07:57.555Z