Nectar: An Active Defense Middleware for Economic Deterrence of Web Scrapers
编号:33
访问权限:仅限参会人
更新:2026-07-22 16:22:20
浏览:1次
In-person
摘要
As automated web scraping represents nearly half of global internet traffic, current perimeter-based security ap-proaches fail to create a deterrent effect against modern distributed attacks. This paper presents Project Nectar, an application-layer active defense middleware designed for the Node.js/Express.js framework. In contrast with passive firewalls aiming at the identification and rejection of the attacker, Nectar concentrates on the economic cost of the attack itself. By combin-ing a Robots Exclusion Protocol compliance checker with invisible bait injection, asynchronous HTTP Tar Pit and cryptographically signed Recursive Dynamic Path Generation (DPG) maze, Nectar creates an endless cycle of resource attrition by delivering low-bandwidth high-latency responses to non-compliant scrapers. An attrition ratio of 1:600 is achieved where a minimal CPU usage by the defender leads to the exhaustion of threads used by distributed botnet scraper attacks at all three adversarial levels. The solution provides a false positive rate of 0 percent in 50,000 simulated user sessions, preserving user experience and maximizing adversary costs. This paper describes Nectar’s threat model, fully implements the algorithmic approach, and evaluates the solution against Level 1 (primitive script), Level 2 (framework-based) and Level 3 (headless browser) adversaries.
关键词
Active defense;web security;tarpit;web scraping
稿件作者
Ishaan Khurana
SRM Institute of Science and Technology *
Abhishek Kumar
SRM Institute of Science and Technology *
Sugan J
SRM Institute of Science and Technology *
发表评论