SurgeProtector: mitigating temporal algorithmic complexity attacks using adversarial scheduling
Nirav Atre, Hugo Sadok, Erica Chiang, Weina Wang, Justine Sherry
Abstract
Denial-of-Service (DoS) attacks are the bane of public-facing network deployments. Algorithmic complexity attacks (ACAs) are a class of DoS attacks where an attacker uses a small amount of adversarial traffic to induce a large amount of work in the target system, pushing the system into overload and causing it to drop packets from innocent users. ACAs are particularly dangerous because, unlike volumetric DoS attacks, ACAs don't require a significant network bandwidth investment from the attacker Today, network functions (NFs) on the Internet must be designed and engineered on a case-by-case basis to mitigate the debilitating impact of ACAs. Further, the resulting designs tend to be overly conservative in their attack mitigation strategy, limiting the innocent traffic that the NF can serve under common-case operation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers7
- Finding Adversarial Inputs for Heuristics using Multi-level OptimizationPooria Namyar, Behnaz Arzani, Ryan Beckett, Santiago Segarra et al.NSDI 2024 · 16 citations
- BBQ: A Fast and Scalable Integer Priority Queue for Hardware Packet SchedulingNirav Atre, Hugo Sadok, Justine SherryNSDI 2024 · 12 citations
- Algorithmic Complexity Attacks on Dynamic Learned IndexesRui Yang, Evgenios M. Kornaropoulos, Yue ChengVLDB 2024 · 10 citations
- The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSECElias Heftrig, Haya Schulmann, Niklas Vogel, Michael WaidnerCCS 2024 · 4 citations
- Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix StrategiesSk Adnan Hassan, Zainab Aamir, Dongyoon Lee, James C. Davis et al.S&P 2023
Related papers
- Acquirer: A Hybrid Approach to Detecting Algorithmic Complexity VulnerabilitiesYinxi Liu, Wei MengCCS 2022 · 3 citations
- DNS Congestion Control in Adversarial SettingsHuayi Duan, Jihye Kim, Marc Wyss, Adrian PerrigSOSP 2024 · 2 citations
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 125 citations
- Tornadoes In The Cloud: Worst-Case Attacks on Distributed Resources SystemsJhonatan Tavori, Hanoch LevyINFOCOM 2021 · 4 citations
- Loopy Hell(ow): Infinite Traffic Loops at the Application LayerYepeng Pan, Anna Ascheman, Christian RossowUSENIX Security 2024 · 4 citations
