Sunday, June 1, 2003

Denial of Service via Algorithmic

Denial of Service via Algorithmic Complexity Attacks:
[...]a new class of low-bandwidth denial of service attacks that exploit algorithmic deficiencies in many common applications' data structures. Frequently used data structures have “average-case” expected running time that’s far more efficient than the worst case. For example, both binary trees and hash tables can degenerate to linked lists with carefully chosen input. We show how an attacker can effectively compute such input, and we demonstrate attacks against the hash table implementations in two versions of Perl, the Squid web proxy, and the Bro intrusion detection system. [...] We show how modern universal hashing techniques can yield performance comparable to commonplace hash functions while being provably secure against these attacks.

e.p.c. posted this at 13:44 GMT on 1-Jun-2003 .

We went to the NY

We went to the NY Liberty home opener against the Washington Mystics. The Liberty won 70-57. Dinner was Korean at Kang-Suh.

e.p.c. posted this at 20:19 GMT on 1-Jun-2003 .

Argh. "Radio Userland" is acting

Argh. "Radio Userland" is acting up again. Still looking at "Moveable Type".

e.p.c. posted this at 22:01 GMT on 1-Jun-2003 .

Playing around tonight with Blogshares.

Playing around tonight with Blogshares. Wonder how long before someone sets up a derivatives market based on the weblog share market.

e.p.c. posted this at 23:19 GMT on 1-Jun-2003 .

Alex has a new essay

Alex has a new essay up at Boxes and Arrows: The Sociobiology of Information Architecture. I’m not sure why, but it tickled my I-need-to-reread Orality and Literacy nerve again.

e.p.c. posted this at 23:56 GMT on 1-Jun-2003 .

Slightly acerbic and eccentric dog walker who masquerades as a web developer and occasional CTO.

Spent five years running the technology side of the circus known as www.ibm.com.

More about me here.

Archives