Effect of Malicious Synchronization

Mun Choon Chan,Ee-chien Chang,Liming Lu,Peng Song Ngiam
DOI: https://doi.org/10.1007/11767480_8
2006-01-01
Abstract:We study the impact of malicious synchronization on com- puter systems that serve customers periodically. Systems supporting au- tomatic periodic updates are common in web servers providing regular news update, sports scores or stock quotes. Our study focuses on the pos- sibility of launching an efiective low rate attack on the server to degrade performance measured in terms of longer processing time and request drops due to timeouts. The attackers are assumed to behave like nor- mal users and send one request per update cycle. The only parameter utilized in the attack is the timing of the requests sent. By exploiting the periodic nature of the updates, a small number of attackers can herd users' update requests to a cluster and arrive in a short period of time. Herding can be used to discourage new users from joining the system and to modify the user arrival distribution, so that the subsequent burst attack will be efiective. While the herding based attacks can be launched with a small amount of resource, they can be easily prevented by adding a small random component to the length of the update interval.
What problem does this paper attempt to address?