<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OAT-015_Denial_of_Service</id>
		<title>OAT-015 Denial of Service - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OAT-015_Denial_of_Service"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OAT-015_Denial_of_Service&amp;action=history"/>
		<updated>2026-05-09T07:47:56Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OAT-015_Denial_of_Service&amp;diff=237787&amp;oldid=prev</id>
		<title>Clerkendweller: /* Indicative Diagram */</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OAT-015_Denial_of_Service&amp;diff=237787&amp;oldid=prev"/>
				<updated>2018-02-16T15:12:05Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Indicative Diagram&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:12, 16 February 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l19&quot; &gt;Line 19:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Indicative Diagram===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Indicative Diagram===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[File:OAT-015_Denial_of_Service.png|500px|link=]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Description ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== Description ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Clerkendweller</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OAT-015_Denial_of_Service&amp;diff=237712&amp;oldid=prev</id>
		<title>Clerkendweller: New page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OAT-015_Denial_of_Service&amp;diff=237712&amp;oldid=prev"/>
				<updated>2018-02-16T11:22:19Z</updated>
		
		<summary type="html">&lt;p&gt;New page&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
This is an automated threat. To view all automated threats, please see the [[:Category:Automated Threat|Automated Threat Category]] page. The OWASP Automated Threat Handbook - Wed Applications ([https://www.owasp.org/index.php/File:Automated-threat-handbook.pdf pdf], print), an output of the [[OWASP Automated Threats to Web Applications|OWASP Automated Threats to Web Applications Project]], provides a fuller guide to  each threat, detection methods and countermeasures. The [https://www.owasp.org/index.php/File:Oat-ontology-decision-chart.pdf threat identification chart] helps to correctly identify the automated threat.&lt;br /&gt;
&lt;br /&gt;
== Definition ==&lt;br /&gt;
&lt;br /&gt;
===OWASP Automated Threat (OAT) Identity Number ===&lt;br /&gt;
&lt;br /&gt;
OAT-015&lt;br /&gt;
&lt;br /&gt;
===Threat Event Name===&lt;br /&gt;
&lt;br /&gt;
Denial of Service&lt;br /&gt;
&lt;br /&gt;
=== Summary Defining Characteristics===&lt;br /&gt;
&lt;br /&gt;
Target resources of the application and database servers, or individual user accounts, to achieve denial of service (DoS).&lt;br /&gt;
&lt;br /&gt;
===Indicative Diagram===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Description ===&lt;br /&gt;
&lt;br /&gt;
Usage may resemble legitimate application usage, but leads to exhaustion of resources such as file system, memory, processes, threads, CPU, and human or financial resources. The resources might be related to web, application or databases servers or other services supporting the application, such as third party APIs, included third-party hosted content, or content delivery networks (CDNs). The application may be affected as a whole, or the attack may be against individual users such as account lockout.&lt;br /&gt;
&lt;br /&gt;
This ontology’s scope excludes other forms of denial of service that a ect web applications, namely HTTP Flood DoS (GET, POST, Header with/without TLS), HTTP Slow DoS, IP layer 3 DoS, and TCP layer 4 DoS. Those protocol and lower layer aspects are covered adequately in other taxonomies and lists.&lt;br /&gt;
&lt;br /&gt;
=== Other Names and Examples ===&lt;br /&gt;
&lt;br /&gt;
Account lockout; App layer DDoS; Asymmetric resource consumption (amplification); Business logic DDoS; Cash overflow; Forced deadlock; Hash DoS; Inefficient code; Indexer DoS; Large files DoS; Resource depletion, locking or exhaustion; Sustained client engagement&lt;br /&gt;
&lt;br /&gt;
=== See Also ===&lt;br /&gt;
&lt;br /&gt;
* [[OAT-005 Scalping]]&lt;br /&gt;
* [[OAT-013 Sniping]]&lt;br /&gt;
* [[OAT-017 Spamming]]&lt;br /&gt;
* [[OAT-019 Account Creation]]&lt;br /&gt;
* [[OAT-021 Denial of Inventory]]&lt;br /&gt;
&lt;br /&gt;
== Cross-References ==&lt;br /&gt;
&lt;br /&gt;
=== CAPEC Category / Attack Pattern IDs ===&lt;br /&gt;
&lt;br /&gt;
* 2 Inducing Account Lockout&lt;br /&gt;
* 25 Forced Deadlock&lt;br /&gt;
* 119 Deplete Resources&lt;br /&gt;
&lt;br /&gt;
=== CWE Base / Class / Variant IDs ===&lt;br /&gt;
&lt;br /&gt;
* 399 Resource Management Errors&lt;br /&gt;
* 645 Overly Restrictive Account Lockout Mechanism&lt;br /&gt;
&lt;br /&gt;
=== WASC Threat IDs ===&lt;br /&gt;
&lt;br /&gt;
* 10 Denial of Service&lt;br /&gt;
&lt;br /&gt;
=== OWASP Attack Category / Attack IDs ===&lt;br /&gt;
&lt;br /&gt;
* Account Lockout Attack&lt;br /&gt;
* [[Cash Overflow]]&lt;br /&gt;
* [[Denial of Service]]&lt;br /&gt;
* [[:Category:Resource Depletion|Resource Depletion]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Automated Threat]]&lt;/div&gt;</summary>
		<author><name>Clerkendweller</name></author>	</entry>

	</feed>