Mitigation of Random Query String DoS via Gossip
Abstract
This paper presents a mitigation scheme to cope with the random query string Denial of Service (DoS) attack, which is based on a vulnerability of current Content Delivery Networks (CDNs). The attack exploits the fact that edge servers composing a CDN, receiving an HTTP request for a resource with an appended random query string never saw before, ask the origin server for a (novel) copy of the resource. Such characteristics can be employed to take an attack against the origin server by exploiting edge servers. Our strategy adopts a simple gossip protocol executed by edge servers to detect the attack. Based on such a detection, countermeasures can be taken to protect the origin server and the CDN against the attack. We provide simulation results that show the viability of our approach.
Keywords
Cite
@article{arxiv.1109.4404,
title = {Mitigation of Random Query String DoS via Gossip},
author = {Stefano Ferretti and Vittorio Ghini},
journal= {arXiv preprint arXiv:1109.4404},
year = {2012}
}
Comments
a revised version will appear in Proc. of the 6th International Conference on Information Systems, Technology and Management (ICISTM-2012), Grenoble, France, Springer Series in Communications in Computer and Information Science (CCIS), March 2012