Skip to main content

Using web-referral architectures to mitigate denial-of-service threats

Publication ,  Journal Article
Wang, X; Reiter, MK
Published in: IEEE Transactions on Dependable and Secure Computing
April 30, 2010

The web is a complicated graph, with millions of websites interlinked together. In this paper, we propose to use this web sitegraph structure to mitigate flooding attacks on a website, using a new web referral architecture for privileged service (WRAPS). WRAPS allows a legitimate client to obtain a privilege URL through a simple click on a referral hyperlink, from a website trusted by the target website. Using that URL, the client can get privileged access to the target website in a manner that is far less vulnerable to a distributed denial-of-service (DDoS) flooding attack than normal access would be. WRAPS does not require changes to web client software and is extremely lightweight for referrer websites, which makes its deployment easy. The massive scale of the web sitegraph could deter attempts to isolate a website through blocking all referrers. We present the design of WRAPS, and the implementation of a prototype system used to evaluate our proposal. Our empirical study demonstrates that WRAPS enables legitimate clients to connect to a website smoothly in spite of a very intensive flooding attack, at the cost of small overheads on the website's ISP's edge routers. We discuss the security properties of WRAPS and a simple approach to encourage many small websites to help protect an important site during DoS attacks. © 2006 IEEE.

Duke Scholars

Published In

IEEE Transactions on Dependable and Secure Computing

DOI

ISSN

1545-5971

Publication Date

April 30, 2010

Volume

7

Issue

2

Start / End Page

203 / 216

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 4606 Distributed computing and systems software
  • 4604 Cybersecurity and privacy
  • 0805 Distributed Computing
  • 0804 Data Format
  • 0803 Computer Software
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Wang, X., & Reiter, M. K. (2010). Using web-referral architectures to mitigate denial-of-service threats. IEEE Transactions on Dependable and Secure Computing, 7(2), 203–216. https://doi.org/10.1109/TDSC.2008.56
Wang, X., and M. K. Reiter. “Using web-referral architectures to mitigate denial-of-service threats.” IEEE Transactions on Dependable and Secure Computing 7, no. 2 (April 30, 2010): 203–16. https://doi.org/10.1109/TDSC.2008.56.
Wang X, Reiter MK. Using web-referral architectures to mitigate denial-of-service threats. IEEE Transactions on Dependable and Secure Computing. 2010 Apr 30;7(2):203–16.
Wang, X., and M. K. Reiter. “Using web-referral architectures to mitigate denial-of-service threats.” IEEE Transactions on Dependable and Secure Computing, vol. 7, no. 2, Apr. 2010, pp. 203–16. Scopus, doi:10.1109/TDSC.2008.56.
Wang X, Reiter MK. Using web-referral architectures to mitigate denial-of-service threats. IEEE Transactions on Dependable and Secure Computing. 2010 Apr 30;7(2):203–216.

Published In

IEEE Transactions on Dependable and Secure Computing

DOI

ISSN

1545-5971

Publication Date

April 30, 2010

Volume

7

Issue

2

Start / End Page

203 / 216

Related Subject Headings

  • Strategic, Defence & Security Studies
  • 4606 Distributed computing and systems software
  • 4604 Cybersecurity and privacy
  • 0805 Distributed Computing
  • 0804 Data Format
  • 0803 Computer Software