Denial of Service via Algorithmic Complexity Attacks

dc.contributor.authorCrosby, Scott A.
dc.contributor.authorWallach, Dan S.
dc.date.accessioned2017-08-02T22:02:59Z
dc.date.available2017-08-02T22:02:59Z
dc.date.issued2003-02-12
dc.date.noteFebruary 12, 2003
dc.description.abstractWe present a new class of low-bandwidth denial of service attacks that exploit algorithmic deficiencies in many common applications' data structures. Frequently used data structures have "average-case'' expected running time that's far more efficient than the worst case. For example, both binary trees and hash tables can degenerate to linked lists with carefully chosen input. We show how an attacker can effectively compute such input, and we demonstrate attacks against the hash table implementations in two versions of Perl, the Squid web proxy, and the Bro intrusion detection system. Using bandwidth less than a typical modem, we can bring a dedicated Bro server to its knees; after six minutes of carefully chosen packets, our Bro server was dropping as much as 71% of its traffic and consuming all of its CPU.
dc.format.extent13 pp
dc.identifier.citationCrosby, Scott A. and Wallach, Dan S.. "Denial of Service via Algorithmic Complexity Attacks." (2003) https://hdl.handle.net/1911/96313.
dc.identifier.digitalTR03-416
dc.identifier.urihttps://hdl.handle.net/1911/96313
dc.language.isoeng
dc.rightsYou are granted permission for the noncommercial reproduction, distribution, display, and performance of this technical report in any format, but this permission is only for a period of forty-five (45) days from the most recent time that you verified that this technical report is still available from the Computer Science Department of Rice University under terms that include this permission. All other rights are reserved by the author(s).
dc.titleDenial of Service via Algorithmic Complexity Attacks
dc.typeTechnical report
dc.type.dcmiText
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
TR03-416.pdf
Size:
418.81 KB
Format:
Adobe Portable Document Format