DocumentCode
653763
Title
NOMAD: Towards non-intrusive moving-target defense against web bots
Author
Vikram, S. ; Chao Yang ; Guofei Gu
Author_Institution
SUCCESS Lab., Texas A&M Univ., College Station, TX, USA
fYear
2013
fDate
14-16 Oct. 2013
Firstpage
55
Lastpage
63
Abstract
Web bots, such as XRumer, Magic Submitter and SENuke, have been widely used by attackers to perform illicit activities, such as massively registering accounts, sending spam, and automating web-based games. Although the technique of CAPTCHA has been widely used to defend against web bots, it requires users to solve some explicit challenges, which is typically interactive and intrusive, resulting in decreased usability. In this paper, we design a novel, non-intrusive moving-target defense system, NOMAD, to complement existing solutions. NOMAD prevents web bots from automating web resource access by randomizing HTML elements while not affecting normal users. Specifically, to prevent web bots uniquely identifying HTML elements for later automation, NOMAD randomizes name/id parameter values of HTML elements in each HTTP form page. We evaluate NOMAD against five powerful state-of-the-art web bots on several popular open source web platforms. According to our evaluation, NOMAD can prevent all these web bots with a relatively low overhead.
Keywords
Internet; computer crime; hypermedia markup languages; CAPTCHA; HTML elements; HTTP form page; Magic Submitter; NOMAD; SENuke; Web bots; Web resource access; XRumer; attackers; illicit activities; nonintrusive moving-target defense system; open source Web platforms; Blogs; CAPTCHAs; HTML; Security; Servers; Social network services; Web pages;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Network Security (CNS), 2013 IEEE Conference on
Conference_Location
National Harbor, MD
Type
conf
DOI
10.1109/CNS.2013.6682692
Filename
6682692
Link To Document