CDN Judo: Breaking the CDN DoS Protection with Itself
Run Guo, Weizhong Li, Baojun Liu, Shuang Hao, Jia Zhang, Haixin Duan, Kaiwen Shen, Jianjun Chen, Ying Liu
摘要
A content delivery network (CDN) improves the accessing performance and availability of websites via its globally distributed network infrastructures, which contributes to the thriving of CDN-powered websites on the Internet. Because CDNpowered websites normally operate important businesses or critical services, attackers are mostly interested in taking down these high-value websites, to achieve severe damage with maximum influence. Because the CDN absorbs distributed attacking traffic with its massive bandwidth resources, it is commonly believed that CDN vendors provide effective DoS protection for the CDNpowered websites. However, we reveal that implementation or protocol weaknesses in the forwarding mechanisms of the CDN can be exploited to break this CDN protection. By sending crafted but legal requests, an attacker can launch an efficient DoS attack against the website origin behind it. In particular, we present three CDN threats in this study. By abusing the HTTP/2 requestconverting behavior and HTTP pre-POST behavior of a CDN, an attacker can saturate the CDN–origin bandwidth and exhaust the connection limits of the origin. What is more concerning is that some CDN vendors use only a small set of traffic forwarding IPs with lower IP-churning rates to establish connections with the origin. This characteristic provides a great opportunity for an attacker to effectively degrade the global availability of a website just by cutting off specific CDN–origin connections. In this work, we examine the CDN request-forwarding behaviors across six well-known CDN vendors and perform real-world experiments to evaluate the severity of the threats. Because the threats are caused by flawed trade-offs made by the CDN vendors between usability and security, we discuss possible mitigation and received positive feedback after responsible disclosure to the aforementioned CDN vendors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Warmonger: Inflicting Denial-of-Service via Serverless Functions in the CloudJunjie Xiong, Mingkui Wei, Zhuo Lu, Yao LiuCCS 2021 · 被引用 21 次
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen 等USENIX Security 2024 · 被引用 5 次
- Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the WildYuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen 等CCS 2024 · 被引用 1 次
- ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based FuzzingLinkai Zheng, Xiang Li, Chuhan Wang, Run Guo 等NDSS 2024
- FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion AnomaliesBahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti 等USENIX Security 2022
它引用的顶会 Paper9
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel 等NDSS 2018 · 被引用 63 次
- CDN-on-Demand: An affordable DDoS Defense via Untrusted CloudsYossi Gilad, Amir Herzberg, Michael Sudkovitch, Michael GobermanNDSS 2016 · 被引用 59 次
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang 等NDSS 2016 · 被引用 44 次
相关 Paper
- Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS AttackRun Guo, Jianjun Chen, Yihang Wang, Keran Mu 等USENIX Security 2023
- Discovering and Measuring CDNs Prone to Domain FrontingKarthika Subramani, Roberto Perdisci, Pierros-Christos Skafidas, Manos AntonakakisWWW 2024 · 被引用 5 次
- H3Act: Automated Measuring Semantic Conversion Anomalies of HTTP/3-to-HTTP/1.1 Translation in CDNsQihang Peng, Siyuan Tian, Yongxin Qiu, Jinyang Huang 等USENIX Security 2026
- Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackHoai Viet Nguyen, Luigi Lo Iacono, Hannes FederrathCCS 2019 · 被引用 41 次
- Cached and Confused: Web Cache Deception in the WildSeyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo 等USENIX Security 2020
