Collected research
CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks
Identifies a new amplification class, Back-to-Origin Amplification, in the pre-fetch and request-rewriting strategies CDNs use when fetching content from origin servers. Because these back-to-origin behaviours favour performance over security, a modest number of attacker requests can drive a CDN into demanding far more traffic from the hosted origin than needed, exhausting its bandwidth. Fourteen popular CDNs were evaluated and mitigations proposed after disclosure to vendors.
Record
- Researcher
- Ziyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen, Run Guo, Cheng Chen and Shaodong Xiao
- Published by
- usenix.org
- Topic
- HTTP
In the archive
Related sources
- USENIX Security '24 - CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks
Tags
This page is the archive's own catalogue record. The research is the work of Ziyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen, Run Guo, Cheng Chen and Shaodong Xiao, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .