DocumentCode :
653763
Title :
NOMAD: Towards non-intrusive moving-target defense against web bots
Author :
Vikram, S. ; Chao Yang ; Guofei Gu
Author_Institution :
SUCCESS Lab., Texas A&M Univ., College Station, TX, USA
fYear :
2013
fDate :
14-16 Oct. 2013
Firstpage :
55
Lastpage :
63
Abstract :
Web bots, such as XRumer, Magic Submitter and SENuke, have been widely used by attackers to perform illicit activities, such as massively registering accounts, sending spam, and automating web-based games. Although the technique of CAPTCHA has been widely used to defend against web bots, it requires users to solve some explicit challenges, which is typically interactive and intrusive, resulting in decreased usability. In this paper, we design a novel, non-intrusive moving-target defense system, NOMAD, to complement existing solutions. NOMAD prevents web bots from automating web resource access by randomizing HTML elements while not affecting normal users. Specifically, to prevent web bots uniquely identifying HTML elements for later automation, NOMAD randomizes name/id parameter values of HTML elements in each HTTP form page. We evaluate NOMAD against five powerful state-of-the-art web bots on several popular open source web platforms. According to our evaluation, NOMAD can prevent all these web bots with a relatively low overhead.
Keywords :
Internet; computer crime; hypermedia markup languages; CAPTCHA; HTML elements; HTTP form page; Magic Submitter; NOMAD; SENuke; Web bots; Web resource access; XRumer; attackers; illicit activities; nonintrusive moving-target defense system; open source Web platforms; Blogs; CAPTCHAs; HTML; Security; Servers; Social network services; Web pages;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications and Network Security (CNS), 2013 IEEE Conference on
Conference_Location :
National Harbor, MD
Type :
conf
DOI :
10.1109/CNS.2013.6682692
Filename :
6682692
Link To Document :
بازگشت