Denial of service (DoS)

An attack on availability that stops legitimate users reaching a system or service, by exhausting its resources or by exploiting a flaw that makes it crash.

A denial of service attack targets availability: its aim is that legitimate users can no longer use a system, network or service. In its narrow sense the term means an attack launched from one source, to separate it from a distributed denial of service attack launched from many. Nothing needs to be stolen or altered for the attack to succeed.

There are two broad ways to deny service. The first is exhaustion: using up a resource the target depends on, such as bandwidth, memory, processing time or connection slots. A SYN flood fills the table of half-open connections, and an application-layer attack sends requests that are expensive for the server to answer. The second is a crash: a malformed input exploits a flaw so the service fails, as the ping of death and the teardrop attack did against older systems. Defences include rate limiting, patching, capacity planning and filtering by the upstream provider.

Exam relevance: a scenario is likely to describe a service that becomes unavailable and ask which property of security is affected, or which attack is at work. Candidates are expected to identify availability, and to tell a single source attack from a distributed one by the number of origins involved.