• Home
  • Search
  • Attacking Websites: Detecting and Preventing HTTP Request Smuggling Attacks
  • Cite Icon3
  • https://doi.org/10.1155/2022/3121177Copy DOI Icon

Attacking Websites: Detecting and Preventing HTTP Request Smuggling Attacks

Show More
  • Abstract
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Until the development of HTTP request smuggling in 2005, individual HTTP requests were considered as independent entities and could not be split or merged. This is a security problem caused by inconsistent content length interpretation approach between web servers, or the web server is not fully implemented in accordance with the RFC standard. It is especially dangerous for web services with complex web architectures. It can route the victims to receive malicious responses, amplify the impact of certain low-threat vulnerabilities, steal user credentials, or bypass network devices’ defenses. However, since its concept and implementation are quite difficult to overcome, it is often ignored by many network administrators, making users who browse such websites vulnerable to the HTTP request smuggling attacks. This paper proposes a general solution to deal with various HTTP request smuggling attacks. A reverse proxy implemented by Flask validates and cleans dubious HTTP requests from the client side and ensures that the original requests comply with RFC standards. Therefore, the website administrators no longer need to configure complicated network settings or customize some open-source project codes to resist or minimize the risk of the HTTP request smuggling attacks. A series of experiments demonstrate that this method is effective and practical.

Loading PDF

Similar Papers
  • Research Article
  • Citations44

Overload control in QoS-aware web servers

  • Feb 06, 2003
  • Computer Networks
  • Huamin Chen +1
  • Conference Article
  • Citations10

HTTP Low and Slow DoS Attack Detection using LSTM based deep learning

  • Nov 24, 2022
  • Bronjon Gogoi +1
  • Conference Article

Detection of web server attacks using principles of immunocomputing

  • Dec 01, 2010
  • V D Kotov +1
  • Book Chapter
  • Citations14

The Reverse C10K Problem for Server-Side Mashups

  • Jan 01, 2009
  • Dong Liu +1
  • Book Chapter

Web Service Enabled Online Laboratory

  • Jan 01, 2010
  • Yuhong Yan +3
  • Conference Article
  • Citations5

Isolating the performance impacts of network interface cards through microbenchmarks

  • Jun 01, 2004
  • Vijay S Pai +2
  • Conference Article
  • Citations5

Reports the current weather conditions on cell phones using web services

  • Jul 01, 2010
  • Shelly Zhao +1
  • Conference Article
  • Citations3

A Secure Real-time Internal and External Network Data Exchange Method Based on Web Service Protocol

  • Aug 01, 2020
  • Zhenfei Qi +4
  • Conference Article

A system for redicting SQLi and XSS Attacks

  • Dec 02, 2021
  • Mehmet Serhan Ercin +1
  • Conference Article
  • Citations12

A Mobile Real-Time Video System Using RTMP

  • Nov 01, 2012
  • Pengyu Zhao +3
  • Conference Article
  • Citations2

Research of Web QoS Control Model Based on Dynamic Resource Reallocation Scheme

  • Dec 01, 2008
  • Junhuai Li +2
  • Research Article
  • Citations40

Web Application Firewall Using Machine Learning and Features Engineering

  • Jun 06, 2022
  • Security and Communication Networks
  • Aref Shaheed +1
  • Research Article
  • Citations32

Efficient on-the-fly Web bot detection

  • Apr 22, 2021
  • Knowledge-Based Systems
  • Grażyna Suchacka +3
  • Conference Article
  • Citations8

Design and Development of A Cloud-Based IDS using Apache Kafka and Spark Streaming

  • Jun 22, 2022
  • Leon Wirz +3
  • Conference Article
  • Citations19

Reasoning with semantics-aware access control policies for geospatial web services

  • Nov 03, 2006
  • Ashraful Alam +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.