Re: HashDoS
| From: | Tom Worster | Date: | Fri, 23 Sep 2016 22:18:15 +0000 |
| Subject: | Re: HashDoS | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96126@lists.php.net to get a copy of this message | ||
On 9/22/16 3:46 AM, Rowan Collins wrote:
I think I'm right in saying that the power of the attack comes in the fact that the total time doesn't scale linearly but exponentially.quadratic is what i read in the previous thread, iirc. even so, it's still a useful gain.
That doesn't exactly answer the question of whether 1000 is the right value, of course.it's the parameter for what's in effect a statistical hypothesis test for randomness, built on the assumption that key patterns that are not hostile are quasi-random and those that are not random are hostile. 1000 seems large if testing randomness, were that the only consideration. but i guess there is a concern that, in some cases, legitimate use could have key patterns with regularities that lead to accumulation in some bins. so it should work, to a useful extent, if there is a parameter value - low enough to give a worthwhile degree of dos attack protection - high enough to false positive only for benign patterns that would in any case cause terrible performance degradation tom