arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Web缓存溢出:利用不精确键实现缓存降级及其他攻击

Web Cache Overflow: Exploiting Imprecise Keys for Cache Degradation and Beyond

Matteo Golinelli, Kaan Onarlioglu, Bruno Crispo

arXiv 2608.04744首次发表:更新:

AI 中文总结

该研究发现Web缓存键不精确可被滥用产生冗余条目,导致缓存降级、源站负载增加甚至DoS攻击,提出精确缓存键设计为关键安全缓解措施。

AI 中文摘要

Web缓存通过在客户端附近存储频繁访问的对象,为当代Web应用提供可扩展性支持。Web缓存在概念上是关联数组,使用由HTTP请求字段组成的缓存键跟踪存储对象。然而,这些缓存键常被网站运营商定义得不精确,这使得客户端可以构造大量针对同一对象但映射到不同缓存键的请求。本研究表明,缓存键中不必要包含的请求元素可被滥用以创建冗余缓存条目。在易受攻击的部署中,持续生成此类冗余副本会降低缓存有效性、增加源站负载,并促进依赖驱逐的攻击。我们的实验在5个独立缓存代理中复现了缓存降级,并表征了这些参数如何影响攻击者成本和缓存命中率,可能导致拒绝服务攻击。我们得出结论,精确的缓存键设计是抵御此滥用向量最直接的缓解措施,应被视为安全最佳实践。

英文摘要

Web caches support the scalability needs of contemporary web applications by storing frequently accessed objects closer to clients. Web caches are conceptually associative arrays, tracking stored objects using cache keys consisting of HTTP request fields. However, these cache keys are often imprecisely defined by website operators. This allows clients to craft a multitude of requests that target the same object, but map to different cache keys. In this work, we show that request elements included unnecessarily in cache keys can be abused to create redundant cache entries. In susceptible deployments, sustained generation of such redundant copies reduces cache effectiveness and increases origin load, facilitating eviction-dependent attacks. Our experiments reproduce cache degradation across five stand-alone caching proxies and characterize how these parameters affect attacker cost and cache hit rate, potentially resulting in denial-of-service attacks. We conclude that precise cache-key design is the most direct mitigation against this abuse vector and should be recognized as a security best practice.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑