Adaptable Practices for Curbing XDoS Attacks
A. Karthigeyan, A. Jaya Ramya · 2012
An XDoS attack intends to exhaust the system resources of the server hosting a web service. An XDoS attack is done through SOAP messages. Cyber-criminals use distributed denial-of-service attacks (DDoS) and XML denial-of-service attacks (XDoS) to extort money from online service providers. This kind of attacks is normally targeted at a particular service provider to exhaust th e network and system resources of the provider. This paper proposes a defense system against XDoS attacks by adapting some of the best practices for countering these XDoS attacks. The system is built on Web Services. It can be constructed and reconfigured easily by an attac k victim. oS attacks were highly popular with the hacker community, and it's easy to understand. A single ―script kiddie‖ attacker with a minimal amount of skill and resources could generate a flood of TCP SYN (for synchronize) requests sufficient to knock a site out of service. Over the years, SYN flood attacks have been largely mitigated by improvements in Web server software and network hardware. An XDoS attack is a content-borne attack whose purpose is to shut down a web service or system running that service. The 3 main strategies used in XDoS attacks are: Oversized payload, External entity references, Entity expansion XML DoS attacks are extremely asymmetric: to deliver the attack payload, an attacker needs to spend only a fraction of the processing power or bandwidth that the victim needs to spend to handle the payload. Worse still, DoS vulnerabilities in code that processes XML are also extremely widespread. Even if you're using thoroughly tested parsers, your code can still be vulnerable unless you take explicit steps to protect it.