Umbra Wiki weakness weakness/CWE-410
Back to wiki

CWE-410 — Insufficient Resource Pool

provenance: imported · CWE: CWE-410

CWE-410: Insufficient Resource Pool

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Incomplete
Likelihood of exploit

Description

The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

Frequently the consequence is a "flood" of connection or sessions.

Common consequences

  • Availability, Integrity, Other: DoS: Crash, Exit, or Restart, Other

Mitigations

Architecture and Design — Do not perform resource-intensive transactions for unauthenticated users and/or invalid requests.

Architecture and Design — Consider implementing a velocity check mechanism which would detect abusive behavior.

Operation — Consider load balancing as an option to handle heavy loads.

Implementation — Make sure that resource handles are properly closed when no longer needed.

Architecture and Design — Identify the system's resource intensive operations and consider protecting them from abuse (e.g. malicious automated script which runs the resources out).

References

  • CWE page: https://cwe.mitre.org/data/definitions/410.html
  • CWE list: https://cwe.mitre.org/data/index.html