3. of Denial of Service (alternative 2022 deck)
Alternative 2022 deck
On January 20, 2022, Adam Shostack posted an article on his blog suggesting some new cards and edits or alternatives for existing cards. You can find his blog post here: https://shostack.org/blog/elevation-of-privilege-2022/.
An attacker can drain our easily replaceable battery (battery, temporary)
Threat |
|
You are not rate limiting the number of simultaneous complex queries a user can perform. By causing excessive use of the processor in calculation or repeated tasks, an attacker could cause energy consumption to peak unexpectedly and therefore drain the battery you are using as the accumulator in a solar-powered installation. |
|
CAPEC |
CAPEC-124 – Shared resource manipulation CAPEC-130 – Excessive allocation |