- Research Article
44
- 10.1016/s1389-1286(03)00178-6
Overload control in QoS-aware web servers
- Feb 06, 2003
- Computer Networks
- Huamin Chen + 1 more +1
Overload control in QoS-aware web servers
Until the development of HTTP request smuggling in 2005, individual HTTP requests were considered as independent entities and could not be split or merged. This is a security problem caused by inconsistent content length interpretation approach between web servers, or the web server is not fully implemented in accordance with the RFC standard. It is especially dangerous for web services with complex web architectures. It can route the victims to receive malicious responses, amplify the impact of certain low-threat vulnerabilities, steal user credentials, or bypass network devices’ defenses. However, since its concept and implementation are quite difficult to overcome, it is often ignored by many network administrators, making users who browse such websites vulnerable to the HTTP request smuggling attacks. This paper proposes a general solution to deal with various HTTP request smuggling attacks. A reverse proxy implemented by Flask validates and cleans dubious HTTP requests from the client side and ensures that the original requests comply with RFC standards. Therefore, the website administrators no longer need to configure complicated network settings or customize some open-source project codes to resist or minimize the risk of the HTTP request smuggling attacks. A series of experiments demonstrate that this method is effective and practical.
Loading PDF
Overload control in QoS-aware web servers
Overload control in QoS-aware web servers
HTTP Low and Slow DoS Attack Detection using LSTM based deep learning
HTTP low and slow DoS is a kind of attack wherein an attacker sends a stream of very slow HTTP requests to a web server. These slow HTTP requests are aimed at specific applications or server resources. By sending HTTP requests very slowly, these attacks waste the server’s resources as the server has to wait for the slow HTTP requests to be completed. HTTP low and slow DoS attacks are primarily used against thread-based web servers like Apache and IIS. By sending very slow requests, these attacks tie up the server threads. This results in a Denial of service for other legitimate users. Since low and slow DoS attacks do not require flooding or sending a large number of HTTP requests, they are not easily detected. Traditional network layer tools cannot detect low and slow DoS attacks and other mitigation and detection strategies are required for the detection of low and slow DoS attacks. In this paper, we propose an LSTM deep learning-based approach for detecting HTTP DoS attacks. The proposed study was conducted on the CIC DoS dataset and a synthetically generated dataset and achieved an impressive accuracy of 0.99.
Read moreDetection of web server attacks using principles of immunocomputing
A new approach to web server attacks detection based on the statistical analysis of HTTP requests and principles of immunocomputing is proposed in the paper. We use a set of legitimate HTTP requests as training data. Each request is represented as its byte frequency distribution. Immunocomputing is used to calculate the binding energy between the training data and sampled HTTP requests. If the binding energy is less than some threshold, an alarm will be triggered. Our approach has been tested with the DARPA data set and the data set collected from the vulnerable web server. We have shown that our approach detects various attacks with a high degree of accuracy.
Read moreThe Reverse C10K Problem for Server-Side Mashups
The original C10K problem [1] studies how to provide reasonable service to 10,000 simultaneous clients or HTTP requests using a normal web server. We call the following problem the reverse C10K problem, or RC10K -- how to support 10,000 simultaneous outbound HTTP requests running on a web server. The RC10K problem can be found in scenarios like service orchestrations and server-side mashups. A server-side mashup needs to send several simultaneous HTTP requests to partner services for each inbound request. Many approaches to improving the performance and scalability of HTTP servers can be applied to tackle the original C10K problem. However, whether these approaches can tackle the reverse C10K problem needs to be verified. In this paper, we discuss the RC10K problem for server-side mashups, and propose a design that takes advantage of advanced I/O, multithreading, and event-driven programming. The results of analysis and experiments show that our design can reduce the resource requirements by almost one order of magnitude with the same performance provided, and it is promising to tackle the RC10K problem.
Read moreWeb Service Enabled Online Laboratory
Online experimentation allows students from anywhere to operate remote instruments at any time. The current techniques constrain users to bind to products from one company and install client side software. We use Web services and Service Oriented Architecture to improve the interoperability and usability of the remote instruments. Under a service oriented architecture for online experiment system, a generic methodology to wrap commercial instruments using IVI and VISA standard as Web services is developed. We enhance the instrument Web services into stateful services so that they can manage user booking and persist experiment results. We also benchmark the performance of this system when SOAP is used as the wire format for communication and propose solutions to optimize performance. In order to avoid any installation at the client side, the authors develop Web 2.0 based techniques to display the virtual instrument panel and real time signals with just a standard Web browser. The technique developed in this article can be widely used for different real laboratories, such as microelectronics, chemical engineering, polymer crystallization, structural engineering, and signal processing.
Read moreIsolating the performance impacts of network interface cards through microbenchmarks
Many factors can prevent a Gigabit Ethernet network interface card (NIC) from achieving line rate in a modern web server. In fact, the various commercially available NICs have different performance characteristics that lead to throughput differences for actual web servers. For example, Figure 1 shows the performance achieved by the thttpd web server for client traces extracted from the Rice University computer science department (CS), a NASA web site (NASA), and the 1998 soccer World Cup tournament (World Cup). The latter two traces are available from the Internet Traffic Archive (http://ita.ee.lbl.gov/). The server system tested includes an AMD Athlon 2600+ XP processor running the FreeBSD 4.7 operating system, 2 GB of DDR SDRAM, a 64-bit/66 MHz PCI bus, and a single 40 GB IDE disk (none of the workloads are disk intensive). The tested systems differ only in their NIC, with the Intel Pro-1000/MT Server and Desktop, Alteon AceNIC with parallelized firmware [2], Netgear GA622T, 3Com 3C996B, and Alteon AceNIC with released firmware arranged from left to right. There are substantial performance differences across the NICs in the web environment, as the fastest NIC consistently achieves 40–60% more throughput than the slowest. A web server interacts with the network in two primary ways: receiving client HTTP requests and sending HTTP responses. Requests are typically quite small, on the order of 200 bytes of ASCII text, while responses vary from empty files to several hundred megabytes. Since web clients and servers communicate using TCP, the server must acknowledge requests, leading to minimum-sized (64-byte) Ethernet frames. Response data must be segmented and encapsulated in Ethernet frames, which allow up to 1460 bytes of TCP content in a maximum-sized (1518-byte) frame. Then, those segments are sent out according to TCP flow control policies based on the receipt of acknowledgments. A high-performance server NIC must thus support data volumes dominated by sends of large
Read moreReports the current weather conditions on cell phones using web services
Mobile technology applications have proven more interesting and more capable with each passing year, and continue to be a technology with new surprises. In this paper, we present a software development for weather report which is motivated as a cell phone programme application for web service. Users can get the latest weather information without accessing to the specific weather website. In addition, weather information can be deployed on any cell phone with internet explorer. Web Services, MIDlet programming is the technology applied in this paper. Weather report is designed as a two-tier structure, web application server and client. Web services are generated and published on the web. On client side, user, on the MIDP platform, can interact with web services with the agreement on SOAP protocol. In this paper, how to deploy web services, and the differences and constraints of MIDlet programming are presented.
Read moreA Secure Real-time Internal and External Network Data Exchange Method Based on Web Service Protocol
With the rapid development of Internet, Web Service technology is gradually applied to many areas of life. The security problems occurred in practical applications of Web Service has received more and more attention from the public. Aiming at the security problems existing in the application process of Web Service, a secure real-time internal and external network data exchange method based on Web Service protocol is proposed in this paper, it is agreed that the external network only allows data exchange with the internal network through the Web Service interface, that is, the internal network starts the Web Service service, the external network accesses the service, and then obtains the internal network data or informs the internal network for business processing. Web attack detection is put to the front end to ensure maximum security of Web Service system, which can meet the requirements of more secure and robust web applications while guaranteeing the business security of visitors.
Read moreA system for redicting SQLi and XSS Attacks
In this study, it is aimed to reduce False-Alarm levels and increase the correct detection rate in order to reduce this uncertainty. Within the scope of the study, 13157 SQLi and XSS type malicious and 10000 normal HTTP Requests were used. All HTTP requests were received from the same web server, and it was observed that normal requests and malicious requests were close to each other. In this study, a novel approach is presented via both digitization and expressing the data with words in the data preprocessing stages. LSTM, MLP, CNN, GNB, SVM, KNN, DT, RF algorithms were used for classification and the results were evaluated with accuracy, precision, recall and F1-score metrics. As a contribution of this study, we can clearly express the following inferences. Each payload even if it seems different which has the same impact maybe that we can clearly view after the preprocessing phase. After preprocessing we are calculating euclidean distances which brings and gives us the relativity between expressions. When we put this relativity as an entry data to machine learning and/or deep learning models, perhaps we can understand the benign request or the attack vector difference.
Read moreA Mobile Real-Time Video System Using RTMP
This paper introduces a mobile real-time video system which is different from other existing real-time video system that is mainly based on wired computers. The system proposed in paper is basically designed to enable users under wireless circumstances to publish what they are capturing with their mobile devices and also watch what others are capturing. The system mainly contains mobile devices with a Flex client application on them, a media server which handles live streams using RTMP (Real-Time Messaging Protocol), and a web server which used to deal with HTTP requests.
Read moreResearch of Web QoS Control Model Based on Dynamic Resource Reallocation Scheme
At present, Web applications and HTTP requests on the Internet are so explosively increasing that a large number of hot Web sites frequently confront with problems of server overloading. And how to provide various web services with high-level quality and satisfactory performance for Web clients has become one of the most urgent points we concern. In order to smoothly solve these problems, we proposed a Web QoS control model based on dynamically reallocating resource on Web server. Facilitated by adopting reflective policy, this model could monitor the real-time state of server resources, schedule and reallocate these resources to satisfy the different client demands in practice. Moreover, this model could utilize a multiple of pre-designed policies that classify HTTP requests based on dynamic admission control scheme and distribute server resource based on dynamic resource reallocation scheme. And we conduct evaluation experiments and compare the QoS performance of this model with the basic best-effort model in IIS6.0. Evaluation results demonstrate our model could significantly reduce response time, warrant stability and reliability when requests exceed the capacity of a Web server.
Read moreWeb Application Firewall Using Machine Learning and Features Engineering
Web application security has become a major requirement for any business, especially with the wide web attacks spreading despite the defensive measures and the continuous development of software frameworks and servers. In this study, we present a proposed model for a web application firewall that used machine learning and features engineering to detect common web attacks. Our proposed model analyses incoming requests to the webserver, parses these requests to extract four features that describe completely HTTP request parts (URL, payload, and headers), and classifies whether a request is normal or an anomaly. We took into consideration the limitation of previous works that use URL and payload only in classification and provided five features that describe and summarize all parts of the HTTP request using features engineering and previous experience in the field of the software security domain. Extracted features are length of request, percentage of characters allowed, percentage of special characters, and attack weight. These features were calculated for four different datasets CSIC 2010, HTTPParams 2015, Hybrid dataset (CSIC 2010 and HTTPParams), and real logs for the compromised web server. We evaluated our proposed model by using these updated datasets with four classification algorithms (Naive Bayes, logistic regression, decision tree, and support vector machine) with two methods (train test split and cross-validation) to negate the probability of overfitting and ensure that features are effective. Features values for a normal request are usually short request length, large allowed character ratio, small special character ratio, and zero attack weight or close to zero. Features values for anomaly requests are large request length, small allowed character percentage, large special character percentage, and very large numerically attack weight. Our proposed model achieved a classification accuracy of 99.6% with datasets used in research studies in this field and 98.8% with datasets of real web servers.
Read moreEfficient on-the-fly Web bot detection
Efficient on-the-fly Web bot detection
Design and Development of A Cloud-Based IDS using Apache Kafka and Spark Streaming
Owing to the efficient resource management, accessibility, and high service availability, cloud computing has been leveraged by several intensive-data processing applications such as big data analytics, social media applications. These applications are typically based on the development of web service and web application. Even though web-based technology offers effective communication and implementation, it has been susceptible to various kinds of attack. In this paper, we investigate possible attacks on REST which is a commonly used protocol for the web service implementation. In REST, HTTP requests are mapped to GET, POST, PUT, and DELETE that have been proven to be prone to common attacks including Automated Brute Forcing on web-based login, HTTP flood attacks, SQL injections (SQLi), and Cross-Site Scripting (XSS). To this end, we propose a design and implementation of the cloud-based IDS to detect such attacks by employing Apache Kafka and Spark streaming to classify and process the high volume of user inputs in REST HTTP communication. To detect the anomalous inputs, we apply the signature-based approach to construct an IDS engine based on a set of known attack patterns that will be leveraged by the Spark Streaming. Specifically, we introduce a new string comparison collection that improves the False Positive (FP) rate in SQL injection detection, which has been a major issue in most proposed IDS currently available. In our experiment, the system is able to determine malicious patterns with high performance as well as to generate SMS alerts and log the event in a Google Cloud Storage Bucket in an efficient manner.
Read moreReasoning with semantics-aware access control policies for geospatial web services
A major obstacle on the way to the successful deployment and operation of Web services on a larger scale is a lack of sophisticated semantics model to represent and communicate the data. To solve the problem, semantics-aware Web services have been proposed. The other major huddle for Web services is the security architecture. Adding semantics to data adds an extra level of security vulnerability because there is scope for rouge agents to retrieve data that are not explicit in the original sources. Our goal is to propose and implement a security framework to thwart such security problems. Not only that, additionally, we demonstrate that proposed semantics can be utilized to cover security instances that would be impossible to achieve in semantics-unaware environment. We define a modular access control policy framework in the context of geospatial data integration platforms. Geospatial semantic Web services can employ the framework to enforce resource access and intelligently make decisions about policy rules. Our framework allows reasoning capabilities at both the resource enforcement point and service discovery point.
Read more