Re: HashDoS

From: Date: Fri, 23 Sep 2016 22:18:15 +0000
Subject: Re: HashDoS
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16  Groups: php.internals 
Request: Send a blank email to internals+get-96126@lists.php.net to get a copy of this message
On 9/22/16 3:46 AM, Rowan Collins wrote:
I think I'm right in saying that the power of the attack comes in the fact that the total time doesn't scale linearly but exponentially.
quadratic is what i read in the previous thread, iirc. even so, it's still a useful gain.
That doesn't exactly answer the question of whether 1000 is the right value, of course.
it's the parameter for what's in effect a statistical hypothesis test for randomness, built on the assumption that key patterns that are not hostile are quasi-random and those that are not random are hostile. 1000 seems large if testing randomness, were that the only consideration. but i guess there is a concern that, in some cases, legitimate use could have key patterns with regularities that lead to accumulation in some bins. so it should work, to a useful extent, if there is a parameter value - low enough to give a worthwhile degree of dos attack protection - high enough to false positive only for benign patterns that would in any case cause terrible performance degradation tom

« previous php.internals (#96126) next »