Umbra Wiki weakness weakness/CWE-405
Back to wiki

CWE-405 — Asymmetric Resource Consumption (Amplification)

provenance: imported · CWE: CWE-405

CWE-405: Asymmetric Resource Consumption (Amplification)

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Incomplete
Likelihood of exploit

Description

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.

Common consequences

  • Availability: DoS: Amplification, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other)

Mitigations

Architecture and Design — An application must make resources available to a client commensurate with the client's access level.

Architecture and Design — An application must, at all times, keep track of allocated resources and meter their usage appropriately.

System Configuration — Consider disabling resource-intensive algorithms on the server side, such as Diffie-Hellman key exchange.

References

  • CWE page: https://cwe.mitre.org/data/definitions/405.html
  • CWE list: https://cwe.mitre.org/data/index.html