arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

重新思考Web应用防火墙

Rethinking Web Application Firewalls

Laurin Brandner, Laurent Vanbever

arXiv 2609.25892首次发表:更新:

发表机构

ETH Zürich(苏黎世联邦理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对应用层DDoS攻击,本文提出高度优化的WAF系统Shimmer,通过JIT编译规则集和高级优化降低延迟,将请求延迟增加从4倍大幅减少。

AI 中文摘要

近年来,应用层(L7)分布式拒绝服务(DDoS)攻击的威胁日益增加。为抵御这些攻击,网络运营商部署了Web应用防火墙(WAF)。WAF是有状态的评分系统,配置有规则集,用于指定恶意流量的特征及处理方式。虽然有效,但WAF成本高昂,且可能使实际应用的请求延迟增加高达4倍。本文介绍了Shimmer,一种高度优化的WAF。Shimmer对规则集进行JIT编译,并应用高级优化以避免评分流水线中的不必要工作。

英文摘要

In recent years, the threat of application-layer (L7) distributed denial-of-service (DDoS) attacks is ever increasing. To defend against them, network operators deploy web application firewalls (WAFs). WAFs are stateful scoring systems which are configured with a rule set that specifies what malicious traffic looks like, and how to handle it. While effective, WAFs are expensive and can increase the request latency of realistic applications by up to $4\times$. This paper introduces Shimmer, a highly optimized WAF. Shimmer JIT-compiles the rule set and applies advanced optimizations to avoid unnecessary work in the scoring pipeline.

DOI:10.3929/ethz-c-000804191

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑