Document details

Torrent Poisoning Protection with a Reverse Proxy Server

Author(s): Godinho, António ; Cardoso, Filipe ; Rosado, José ; Sá, Filipe ; Caldeira, Filipe

Date: 2022

Persistent ID: http://hdl.handle.net/10400.15/4670

Origin: Repositório Científico do Instituto Politécnico de Santarém

Subject(s): Torrent poisoning; Index poisoning; HAProxy; Reversed proxy; Distributed Denial-of-Service (DDoS) flooding attack


Description

A Distributed Denial-of-Service attack uses multiple sources operating in concert to attack a network or site. A typical DDoS flood attack on a website targets a web server with multiple valid requests, exhausting the server’s resources. The participants in this attack are usually compromised/infected computers controlled by the attackers. There are several variations of this kind of attack, and torrent index poisoning is one. A Distributed Denial-of-Service (DDoS) attack using torrent poisoning, more specifically using index poisoning, is one of the most effective and disruptive types of attacks. These web flooding attacks originate from BitTorrent-based file-sharing communities, where the participants using the BitTorrent applications cannot detect their involvement. The antivirus and other tools cannot detect the altered torrent file, making the BitTorrent client target the webserver. The use of reverse proxy servers can block this type of request from reaching the web server, preventing the severity and impact on the service of the DDoS. In this paper, we analyze a torrent index poisoning DDoS to a higher education institution, the impact on the network systems and servers, and the mitigation measures implemented.

Document Type Journal article
Language English
Contributor(s) Repositório Científico do Instituto Politécnico de Santarém
facebook logo  linkedin logo  twitter logo 
mendeley logo

Related documents

No related documents