Learning path

Full curriculum

Full curriculum

Unit content

Resource exhaustion and denial of service

A system can fail its security goals even when no secret is stolen and no data is modified. A denial-of-service attack targets availability by making legitimate work unavailable or excessively slow.

An adversary may exhaust resources such as

  • CPU time;
  • memory;
  • network bandwidth;
  • database connections;
  • file descriptors;
  • worker threads or request queues.

The important quantity is often asymmetry: how much expensive server work can be triggered by a small amount of attacker effort.

Defenses include bounded queues, timeouts, quotas, request-size limits, admission control, caching and rate limiting. The appropriate control depends on which resource is scarce and which clients or accounts should be allowed to consume it.

Rate limiting is not only a login defense; it is one form of resource policy. Conversely, a rate limit that stores unlimited per-client state can itself become a resource-exhaustion target.

Availability defenses should therefore bound both the work performed and the state retained for untrusted demand.