설명
제품이 제한된 자원의 할당과 유지 관리를 제대로 제어하지 않아 자원이 고갈될 수 있으며, 이는 서비스 거부로 이어질 수 있습니다.
잠재적 영향
- 서비스 거부: 시스템이 속도가 느려지거나, 충돌하거나, 사용자 접근이 제한될 수 있습니다.
- 리소스 오버로드: CPU, 메모리 등 제한된 자원 소비 증가로 시스템이 마비될 수 있습니다.
해결 방법
- 자원 할당 시 최대 할당량을 정의하여 무제한 할당을 방지하세요.
- 실행 후 자원을 확실히 반환하도록 코드를 설계하세요.
- 파일, 데이터베이스 연결 등을 사용한 후 닫는 것을 잊지 마세요.
- 정해진 자원 사용 이상의 요청에 대해 스로틀링을 적용하세요.
예시
다운로드 작업을 생략한 Spring 컨트롤러 발췌입니다. 변경 후의 카운터는 한 컨트롤러 인스턴스에서 동기적으로 실행 중인 메서드 수를 제한합니다. 실제 전송 작업은 try 안에서 완료되어야 하며 비동기 전송·여러 인스턴스의 전체 한도는 별도로 관리하세요. 파일 경로 검증, 전송 크기·시간 제한과 필요한 import는 생략했습니다.
변경 전
java
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class FileDownloadController {
@GetMapping("/download")
public void downloadFile(@RequestParam String fileName) {
// 대규모 파일 다운로드 메소드를 호출하지만 모든 연결에 무제한 리소스를 사용
File file = new File(fileName);
// 실제 파일 다운로드 로직
}
}
변경 후
java
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestParam;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class FileDownloadController {
private static final int MAX_CONNECTIONS = 10; // 최대 연결 수를 제한
private AtomicInteger activeConnections = new AtomicInteger(0);
@GetMapping("/download")
public ResponseEntity<String> downloadFile(@RequestParam String fileName) {
if (activeConnections.incrementAndGet() > MAX_CONNECTIONS) {
activeConnections.decrementAndGet();
return ResponseEntity.status(HttpStatus.TOO_MANY_REQUESTS).body("Too Many Requests");
}
try {
File file = new File(fileName);
// 실제 파일 다운로드 로직
} finally {
activeConnections.decrementAndGet();
}
return ResponseEntity.ok("Download started");
}
}
설명:
- 변경 전: 비제어된 대규모 파일 다운로드는 사용할 수 있는 리소스를 고갈 시켜 시스템을 느리게 하거나 멈추게 할 수 있습니다.
- 변경 후: 동시 작업 수를 제한해 자원 고갈 위험을 줄입니다.
finally에서 카운터를 줄이지만, 이것이 파일이나 네트워크 자원을 자동으로 닫는 것은 아닙니다.
관련 CVE
- CVE-2022-21668: Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive memory consumption (CWE-789) or an integer overflow (CWE-190).
- CVE-2020-7218: Go-based workload orchestrator does not limit resource usage with unauthenticated connections, allowing a DoS by flooding the service
- CVE-2020-3566: Resource exhaustion in distributed OS because of "insufficient" IGMP queue management, as exploited in the wild per CISA KEV.