2010 European Conference on Computer Network Defense 2010
DOI: 10.1109/ec2nd.2010.7
|View full text |Cite
|
Sign up to set email alerts
|

HTTPreject: Handling Overload Situations without Losing the Contact to the User

Abstract: Abstract-The web is a crucial source of information nowadays. At the same time, web applications become more and more complex. Therefore, a spontaneous increase in the number of visitors, e.g., based on news reports or events, easily brings a web server in an overload situation. In contrast to the classical model of distributed denial of service (DDoS) attacks, such a so-called flash effect situation is not triggered by a bulk of bots just aiming at hurting the system but by humans with a high interest in the … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
12
0

Year Published

2014
2014
2017
2017

Publication Types

Select...
2
2

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(12 citation statements)
references
References 11 publications
0
12
0
Order By: Relevance
“…HTTPredirect is a modified version of the HTTPreject module proposed in a previous study and serves as the front end to the Web server to be protected. It is similar to the HTTPreject system in that of being stateless and in the way it functions, except for the following: Instead of responding with 200 OK message, it responds with 307 Temporary Redirect, which automatically redirects clients to one of the CAPTCHA nodes selected at random (or based on some other selection policy). It passes through connection requests relayed by the CAPTCHA nodes to the Web server.…”
Section: System Architecturementioning
confidence: 99%
See 3 more Smart Citations
“…HTTPredirect is a modified version of the HTTPreject module proposed in a previous study and serves as the front end to the Web server to be protected. It is similar to the HTTPreject system in that of being stateless and in the way it functions, except for the following: Instead of responding with 200 OK message, it responds with 307 Temporary Redirect, which automatically redirects clients to one of the CAPTCHA nodes selected at random (or based on some other selection policy). It passes through connection requests relayed by the CAPTCHA nodes to the Web server.…”
Section: System Architecturementioning
confidence: 99%
“…Flash crowd events are usually predictable because they are associated with certain events (eg, new movie release, election results, and student registration). However, in other cases, flash crowd events may happen suddenly as a result of a major accident or a world event, such as the volcano ash that affected Europe's air traffic, whereby flight delays and cancelations ignited travelers to keep checking their flight status over and over . While a website can provision enough resources in advance to handle the expected overload situation, this provisioning can be very costly or technically difficult to set up within a short time.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations
“…The five categories are high rate DDoS (HR-DDoS) attacks, low rate DDoS (LR-DDoS) attacks, flash crowd (FC) attacks, outer blocking (OB), and traceback and client validation (TB and CV). Various researchers [1, 1923] highlighted that the protective scheme or framework should protect web applications from high rate DDoS (HR-DDoS) attacks, whilst other researchers suggested it should provide a protection for web applications from Low Rate DDoS (LR-DDoS) attacks [24, 26]. Other researchers [26, 27] claimed that it should provide protection against flash crowd (FC) attacks.…”
Section: Literature Reviewmentioning
confidence: 99%