Denial of Service via Algorithmic Complexity Attacks

dc.contributor.authorCrosby, Scott A.en_US
dc.contributor.authorWallach, Dan S.en_US
dc.date.accessioned2017-08-02T22:02:59Zen_US
dc.date.available2017-08-02T22:02:59Zen_US
dc.date.issued2003-02-12en_US
dc.date.noteFebruary 12, 2003en_US
dc.description.abstractWe present a new class of low-bandwidth denial of service attacks that exploit algorithmic deficiencies in many common applications' data structures. Frequently used data structures have "average-case'' expected running time that's far more efficient than the worst case. For example, both binary trees and hash tables can degenerate to linked lists with carefully chosen input. We show how an attacker can effectively compute such input, and we demonstrate attacks against the hash table implementations in two versions of Perl, the Squid web proxy, and the Bro intrusion detection system. Using bandwidth less than a typical modem, we can bring a dedicated Bro server to its knees; after six minutes of carefully chosen packets, our Bro server was dropping as much as 71% of its traffic and consuming all of its CPU.en_US
dc.format.extent13 ppen_US
dc.identifier.citationCrosby, Scott A. and Wallach, Dan S.. "Denial of Service via Algorithmic Complexity Attacks." (2003) https://hdl.handle.net/1911/96313.en_US
dc.identifier.digitalTR03-416en_US
dc.identifier.urihttps://hdl.handle.net/1911/96313en_US
dc.language.isoengen_US
dc.rightsYou are granted permission for the noncommercial reproduction, distribution, display, and performance of this technical report in any format, but this permission is only for a period of forty-five (45) days from the most recent time that you verified that this technical report is still available from the Computer Science Department of Rice University under terms that include this permission. All other rights are reserved by the author(s).en_US
dc.titleDenial of Service via Algorithmic Complexity Attacksen_US
dc.typeTechnical reporten_US
dc.type.dcmiTexten_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
TR03-416.pdf
Size:
418.81 KB
Format:
Adobe Portable Document Format