翻訳と辞書
Words near each other
・ Billion
・ Billion (company)
・ Billion (disambiguation)
・ Billion cubic metres of natural gas
・ Billion Dollar Babies
・ Billion Dollar Babies (song)
・ Billion Dollar Baby
・ Billion Dollar Boner
・ Billion Dollar Brain
・ Billion Dollar Bully
・ Billion Dollar Day
・ Billion Dollar Gift and Mutual Aid
・ Billion Dollar Gravy
・ Billion Dollar Limited
・ Billion Dollar Sound
Billion laughs
・ Billion Lights
・ Billion Oyster Project
・ Billion Soul Harvest
・ Billion Tree Campaign
・ Billion-Dollar Brain
・ Billionaire
・ Billionaire (disambiguation)
・ Billionaire (song)
・ Billionaire Boy
・ Billionaire Boys Club
・ Billionaire Boys Club (clothing retailer)
・ Billionaire Boys Club (disambiguation)
・ Billionaire Boys Club (film)
・ Billionaires for Bush


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

Billion laughs : ウィキペディア英語版
Billion laughs
In computer security, a billion laughs attack is a type of denial-of-service (DoS) attack which is aimed at parsers of XML documents.
It is also referred to as an XML bomb or as an exponential entity expansion attack.
== Details ==
The example attack consists of defining 10 entities, each defined as consisting of 10 of the previous entity, with the document consisting of a single instance of the largest entity, which expands to one billion copies of the first entity.
In the most frequently cited example, the first entity is the string "lol", hence the name "billion laughs". The amount of computer memory used would likely exceed that available to the process parsing the XML (it certainly would have at the time the vulnerability was first reported).
While the original form of the attack was aimed specifically at XML parsers, the term may be applicable to similar subjects as well.〔
The problem was first reported as early as 2002,〔(【引用サイトリンク】 SecurityFocus )〕 but began to be widely addressed in 2008.
Defenses against this kind of attack include capping the memory allocated in an individual parser if loss of the document is acceptable, or treating entities symbolically and expanding them lazily only when (and to the extent) their content is to be used.

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「Billion laughs」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.