• DocumentCode
    653763
  • Title

    NOMAD: Towards non-intrusive moving-target defense against web bots

  • Author

    Vikram, S. ; Chao Yang ; Guofei Gu

  • Author_Institution
    SUCCESS Lab., Texas A&M Univ., College Station, TX, USA
  • fYear
    2013
  • fDate
    14-16 Oct. 2013
  • Firstpage
    55
  • Lastpage
    63
  • Abstract
    Web bots, such as XRumer, Magic Submitter and SENuke, have been widely used by attackers to perform illicit activities, such as massively registering accounts, sending spam, and automating web-based games. Although the technique of CAPTCHA has been widely used to defend against web bots, it requires users to solve some explicit challenges, which is typically interactive and intrusive, resulting in decreased usability. In this paper, we design a novel, non-intrusive moving-target defense system, NOMAD, to complement existing solutions. NOMAD prevents web bots from automating web resource access by randomizing HTML elements while not affecting normal users. Specifically, to prevent web bots uniquely identifying HTML elements for later automation, NOMAD randomizes name/id parameter values of HTML elements in each HTTP form page. We evaluate NOMAD against five powerful state-of-the-art web bots on several popular open source web platforms. According to our evaluation, NOMAD can prevent all these web bots with a relatively low overhead.
  • Keywords
    Internet; computer crime; hypermedia markup languages; CAPTCHA; HTML elements; HTTP form page; Magic Submitter; NOMAD; SENuke; Web bots; Web resource access; XRumer; attackers; illicit activities; nonintrusive moving-target defense system; open source Web platforms; Blogs; CAPTCHAs; HTML; Security; Servers; Social network services; Web pages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Network Security (CNS), 2013 IEEE Conference on
  • Conference_Location
    National Harbor, MD
  • Type

    conf

  • DOI
    10.1109/CNS.2013.6682692
  • Filename
    6682692