Nectar: An Active Defense Middleware for Economic Deterrence of Web Scrapers
ID:33
Submission ID:271 View Protection:ATTENDEE
Updated Time:2026-07-22 16:22:20
Hits:24
Online
Start Time:2026-07-30 17:20 (Asia/Kolkata)
Duration:15min
Session:[S6] Artificial Intelligence Use Cases » [S6-2] Artificial Intelligence Use Cases
Presentation File
Tips: The file permissions under this presentation are only for participants. You have not logged in yet and cannot view it temporarily.
Abstract
As automated web scraping represents nearly half of global internet traffic, current perimeter-based security ap-proaches fail to create a deterrent effect against modern distributed attacks. This paper presents Project Nectar, an application-layer active defense middleware designed for the Node.js/Express.js framework. In contrast with passive firewalls aiming at the identification and rejection of the attacker, Nectar concentrates on the economic cost of the attack itself. By combin-ing a Robots Exclusion Protocol compliance checker with invisible bait injection, asynchronous HTTP Tar Pit and cryptographically signed Recursive Dynamic Path Generation (DPG) maze, Nectar creates an endless cycle of resource attrition by delivering low-bandwidth high-latency responses to non-compliant scrapers. An attrition ratio of 1:600 is achieved where a minimal CPU usage by the defender leads to the exhaustion of threads used by distributed botnet scraper attacks at all three adversarial levels. The solution provides a false positive rate of 0 percent in 50,000 simulated user sessions, preserving user experience and maximizing adversary costs. This paper describes Nectar’s threat model, fully implements the algorithmic approach, and evaluates the solution against Level 1 (primitive script), Level 2 (framework-based) and Level 3 (headless browser) adversaries.
Keywords
Active defense;web security;tarpit;web scraping
Speaker
Comment submit