• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Lin, Ziyu (Lin, Ziyu.) [1] | Lin, Zhiwei (Lin, Zhiwei.) [2] | Liu, Ximeng (Liu, Ximeng.) [3] (Scholars:刘西蒙) | Chen, Jianjun (Chen, Jianjun.) [4] | Guo, Run (Guo, Run.) [5] | Chen, Cheng (Chen, Cheng.) [6] | Xiao, Shaodong (Xiao, Shaodong.) [7]

Indexed by:

EI

Abstract:

Content Delivery Networks (CDNs) provide high availability, speed up content delivery, and safeguard against DDoS attacks for their hosting websites. To achieve the aforementioned objectives, CDN designs several back-to-origin strategies that proactively pre-pull resources and modify HTTP requests and responses. However, our research reveals that these back-to-origin strategies prioritize performance over security, which can lead to excessive consumption of the website's bandwidth. We have proposed a new class of amplification attacks called Back-to-Origin Amplification (BtOAmp) Attacks. These attacks allow malicious attackers to exploit the back-to-origin strategies, triggering the CDN to greedily demand more-than-necessary resources from websites, which finally blows the websites. We evaluated the feasibility and real-world impacts of BtOAmp attacks on fourteen popular CDNs. With real-world threat evaluation, our attack threatens all mainstream websites hosted on CDNs. We responsibly disclosed the details of our attack to the affected CDN vendors and proposed possible mitigation solutions. © USENIX Security Symposium 2024.All rights reserved.

Keyword:

Amplification Carrier sense multiple access Frequency division multiple access HTTP Hypertext systems Peer to peer networks Websites

Community:

  • [ 1 ] [Lin, Ziyu]Fuzhou University, China
  • [ 2 ] [Lin, Ziyu]Tsinghua University, China
  • [ 3 ] [Lin, Zhiwei]Sichuan University, China
  • [ 4 ] [Lin, Zhiwei]Tsinghua University, China
  • [ 5 ] [Liu, Ximeng]Fuzhou University, China
  • [ 6 ] [Chen, Jianjun]Tsinghua University, China
  • [ 7 ] [Guo, Run]Tsinghua University, China
  • [ 8 ] [Chen, Cheng]Fuzhou University, China
  • [ 9 ] [Xiao, Shaodong]Fuzhou University, China

Reprint 's Address:

Email:

Show more details

Related Keywords:

Source :

Year: 2024

Page: 5717-5734

Language: English

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 9

Online/Total:257/9680204
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1