Abstract
A slow HTTP POST attack is an application-layer distributed denial-of-service attack targeting web servers. The attacker simulates a legitimate user with a slow network speed and continues to send requests, resulting in server resources being unavailable for a long time to other users. The similarity to legitimate behavior makes it challenging to identify such attack traffic. To address this issue, this paper proposes a responsive defense mechanism that exploits programmable network devices to identify attack traffic based on HTTP headers. With information that is not available from legacy network devices, this method can identify different types of requests and apply limitations. This approach achieves a distributed, source-based defense capability by utilizing data plane programmability, making it a scalable solution. The simulation results show that the approach is effective and accurate against slow HTTP POST attacks.
Cite
CITATION STYLE
Hsieh, C. Y., Chen, H. Y., Shen, S. H., Hung, C. H., & Lin, T. N. (2022). A P4-based content-aware approach to mitigate slow HTTP POST attacks. In EuroP4 2022 - Proceedings of the 5th International Workshop on P4 in Europe, Part of CoNEXT 2022 (pp. 8–14). Association for Computing Machinery, Inc. https://doi.org/10.1145/3565475.3569075
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.