RSS Traffic like a DDos Attack...

This is the beginning of a big problem, expecially for the future and for sites with lots of accesses...

On an article just appeared on InfoWorld, Chad Dickenson points the attention to a problem: RSS feed Readers are useful for obtaining informations in real time, but they can have a dangerous behaviour. He observed that  "every hour, Infoworld sees a massive surge of RSS newsreader activity that has all the characteristics of a distributed DoS attack. So many requests in such a short period of time are creating scaling issues".

We can observ this problem also on other sites and I think it's time to think to avoid these types of problems.

The basic problem with RSS now is that it's based on a "pull" method: every RSS clients that wants to retrieve informations have to make periodic requests to the server only for see if there's something available. You can see that, if the requests are a big quantity, some problems may occour.

Solutions or ideas to avoid this? Maybe not a "pull" method, but a "push" method: if the feed source was able to push the feeds to the clients, there will be a significant decrease of traffic on the network. Obviously, this type of actions is not so simple... for example, clients must be subscribed to the feed server, so a way of subscribtion is necessary. The server obviously will push the informations only on subscribed (and recognized) clients.

Yes... recognized... a way of authentication I think is necessary (maybe a key exchangement between news client and news server).

These are only ideas... this is a problem that must be take in consideration, NOW!

Print | posted on Tuesday, July 20, 2004 4:29 PM

Comments on this post

# re: RSS Traffic like a DDos Attack...

Requesting Gravatar...
RSS is a mess, we should all GetAtom!
Left by paul on Jul 20, 2004 12:57 PM

# re: RSS Traffic like a DDos Attack...

Requesting Gravatar...
I don't know if Atom could be the solution...
Left by Stefano Demiliani on Jul 20, 2004 1:00 PM

# RSS DDOS

Requesting Gravatar...
Left by Matt's Blog on Jul 21, 2004 7:06 AM

# RSS DDOS

Requesting Gravatar...
Left by Matt's Blog on Jul 21, 2004 7:06 AM

# RSS DDOS

Requesting Gravatar...
Left by Matt's Blog on Jul 21, 2004 7:06 AM

# re: RSS Traffic like a DDos Attack...

Requesting Gravatar...
It seems to me that the problem is that RSS has been extended beyond its original purpose. Originally, news sites allowed their content to be syndicated, and sites got the feed relatively frequently.

But now with popular sites using RSS and legions subscribing to them with readers, this paradigm no longer applies. A more sensible solution would be to be more like e-mail; a user starts his/her reader up daily and gets the news about what's happened.

Of course, caching wouldn't hurt either.
Left by Zooplah on Jul 22, 2004 8:11 PM

# re: RSS Traffic like a DDos Attack...

Requesting Gravatar...
I think that a push method could be a possible solution... news are sent periodically to all active subscribers for a feed... no big request from the feed readers.
Left by Stefano Demiliani on Jul 23, 2004 10:38 AM

# re: RSS Traffic like a DDos Attack...

Requesting Gravatar...
I think Chad's actions post this event prove there's no problem w/ RSS and he was just crying wolf. And to all the sheep that followed him...

http://www.kbcafe.com/rss/?guid=20040721043921
Left by Randy Charles Morin on Sep 16, 2004 10:29 AM

Your comment:

 (will show your gravatar)
 
Please add 8 and 8 and type the answer here: