Research libp2p DDoS attack mitigation #538
Labels
Let's discuss
Discussion for general feedback and positive criticism :)
next-sprint-candidate
protocol
Protocol Team tickets
question
Further information is requested
Problem to be solved
Charon nodes in a cluster communicate via libp2p. There are multiple libp2p protocols inside charon (dkg/qbft/ping/parsigex). A Byzantine node can DDoS other nodes by spamming them with valid (or invalid) connections and messages, causing OOM and or CPU problems.
DDoS can happen on the following resources:
This is however a common problem, so there might be existing solutions to the problem.
Proposed solution
connmgr.ConnManager
to limit connectionsnetwork.ResourceManager
to limit memory, streams, connections, and file descriptorsWrite a document with findings and recommendations.
Out of Scope
Nothing needs to be implemented yet.
The text was updated successfully, but these errors were encountered: