CWE-410 — Insufficient Resource Pool
CWE-410: Insufficient Resource Pool
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Class |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.
Frequently the consequence is a "flood" of connection or sessions.
Common consequences
- Availability, Integrity, Other: DoS: Crash, Exit, or Restart, Other
Mitigations
Architecture and Design — Do not perform resource-intensive transactions for unauthenticated users and/or invalid requests.
Architecture and Design — Consider implementing a velocity check mechanism which would detect abusive behavior.
Operation — Consider load balancing as an option to handle heavy loads.
Implementation — Make sure that resource handles are properly closed when no longer needed.
Architecture and Design — Identify the system's resource intensive operations and consider protecting them from abuse (e.g. malicious automated script which runs the resources out).
References
- CWE page: https://cwe.mitre.org/data/definitions/410.html
- CWE list: https://cwe.mitre.org/data/index.html