Application-level Denial of Service

No ratings

Presented at Beacon 2014 by

While traffic flooding attacks are generally what come to mind when one hears the term "Denial of Service", this is only a very small slice of attacks on availability. Traffic flooding is so often used and so popular because there is never a way to fully protect against it, only ways to reduce its usefulness. To borrow a quote: "Brute force always works. If it doesn't work, you're not using enough." However, traffic flooding attacks are a war of attrition. It all comes down to whoever has the most resources. The more interesting attacks on availability are asymmetric; that is, one person with one 28.8k dialup connection can take down an entire web server. What's more, some of these attacks can be very difficult to block using technologies like WAF and IPS, because they look like completely normal traffic. This talk will discuss various asymmetric denial of service attacks from the historical to the modern to provide a broader understanding of how attacks on availability can be achieved.