首页> 外文会议>IEEE Symposium on Reliable Distributed Systems >Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation
【24h】

Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation

机译:滥用CDN以获得娱乐和利润:CDN的原始验证中的安全性问题

获取原文

摘要

Content Delivery Networks (CDNs) are critical Internet infrastructure. Besides high availability and high performance, CDNs also provide security services such as anti-DoS and Web Application Firewalls to CDN-powered websites. However, the massive resources of CDNs may also be leveraged by attackers exploiting their architectural, implementation, or operational weaknesses. In this paper, we show that today's CDN operation is overly loose in customer-controlled forwarding policy and the lack of origin validation leads to a wide range of abuse cases such as DoS attack and stealthy port scan. We systematically study these abuse cases and demonstrate their feasibility in popular CDNs. Further, we evaluate the impact of these abuses by discovering that there are millions of CDN edge servers, and a substantial fraction of them can be abused. Lastly, we propose mitigation solutions against such abuses and discuss their feasibility.
机译:内容交付网络(CDN)是关键的Internet基础结构。除了高可用性和高性能外,CDN还为CDN驱动的网站提供安全服务,例如反DoS和Web应用程序防火墙。但是,攻击者可能会利用CDN的大量资源来利用其体系结构,实现或操作上的弱点。在本文中,我们表明,当今的CDN操作在客户控制的转发策略中过于宽松,缺乏原始验证会导致大量滥用情况,例如DoS攻击和隐匿端口扫描。我们系统地研究了这些滥用案例,并证明了它们在流行的CDN中的可行性。此外,我们通过发现有数百万个CDN边缘服务器来评估这些滥用的影响,其中很大一部分都可以被滥用。最后,我们提出针对此类滥用的缓解措施并讨论其可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号