Return
WebTrap: Adaptive detection and mitigation of algorithmic complexity attacks on web endpoints
H
DOI:10.1016/j.cose.2026.105089.png)
Abstract
En 中文
This work presents WebTrap, a dynamic real-time algorithmic complexity attack detection and mitigation framework. WebTrap monitors the endpoints in a web service and uses sequential probability ratio testing to dynamically produce a current attack confidence given signals from the system’s computational resources. Under WebTrap’s threat model, the attacker conducts semi-automated, adaptive, and non-volumetric complexity attacks. The attack detection method is training-less, application-agnostic, avoids anomaly detection, and analyzes the attack’s outcome as opposed to the client request behavior. To boost attack confidence, WebTrap installs deceptive canary endpoints that mimic the functionality of the web service but are not requested by legitimate clients. The mitigation framework extends the use of canaries and deploys decoy endpoints that absorb the attack effort, reducing the computational load from malicious requests on the real system endpoints. WebTrap is systematically evaluated using three attack strategies on a Flask-based testbed and a WordPress plugin, showing detection of attacks with high accuracy and reduced overall system overhead as a result of the decoy-based mitigation.
Journal
C
IF:
5.4
Papers:
164
Citations:
0
Organization
No organization information available
