Exhaustion Attack
Updated 2026-08-04
INTRODUCTION
English translation pending.
CORE DEFINITION
A class of denial-of-service attack in which the adversary never compromises the target directly but instead drains a finite resource it depends on, including CPU cycles, memory, connection slots, disk space, or bandwidth. Because the resource is exhausted rather than corrupted, the system remains intact yet unresponsive to legitimate users. The defining qualification is that the attack targets a bottleneck, so defense requires identifying which resource is actually constrained. The same logic applies outside computing, where a rival can exhaust a competitor's cash or attention through endless litigation, price wars, or public relations campaigns rather than by beating its product.
SCAFFOLDING EFFECT
Reduce cognitive load
- Bottleneck first: identify which finite resource the system depends on before designing any defense. - Rival attrition: ask whether a competitor is trying to drain your cash or attention rather than beat your product. - Slack reserve: keep redundant capacity that stays idle during normal operation.
Anchor fast decisions
Every system has at least one scarce resource that all requests must pass through. Saturating that resource makes the system unable to admit new work, and the exhaustion requires no exploit and no elevated privilege. Slow, low-volume consumption reaches the same end state over a longer window, which is why volume-based alarms often miss it.
MINIMUM ACTION
In progress 0/1Practice this model in one real situation:
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more
Source support: Explicit
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Resource_exhaustion_attackverified
PRIVATE NOTES · Only visible to you
SAVED Q&A
ENTRY Q&A · Private saving available
Ask with a clear boundary
thinkingmodels answers from published entry context only.
Your question is sent to thinkingmodels. The answer uses public entry context only.
RELATED MODELS