Urgent.News

What's breaking now, across thousands of outlets.

Tech

Why Fixed-Window Rate Limiters Fail (And How to Fix Them with Math)

If you’ve ever built an Express API, you’ve probably reached for standard rate-limiting middleware to protect your login or payment endpoints from DDoS and brute-force attacks. Under the hood, most simple limiters use a Fixed-Window Counter . It’s easy to write: count incoming requests, and once the minute rolls over, reset the counter to zero. However, from a security and algorithmic standpoint,…

The Fixed-Window Counter rate limiting method has a significant flaw that can be exploited by attackers. This vulnerability allows bursts of requests during a brief period, bypassing the imposed limit. For example, if an endpoint permits 100 requests per minute, an attacker can fire 100 requests at 12:00:59, and then another 100 requests at 12:01:01.

Since the counter resets every minute, the server perceives the requests as legitimate, while in reality, the attacker has overloaded the backend with 200 requests in a 2-second window, potentially causing system failure or enabling attacks such as credential stuffing. To counter this issue, the Sliding Window Counter method can be employed, utilizing a continuously sliding window instead of a fixed clock reset.

This approach prevents boundary spikes by accurately accounting for request bursts. In contrast to the memory-intensive Sliding Window Log, the Sliding Window Counter maintains only two integers: the request count from the previous window and the count from the current window. By weighting the previous window based on the elapsed time in the current window, we estimate the total requests within the current window.

The time complexity remains constant at O(1), and the memory footprint is also optimized at O(1), requiring just two counter variables per IP. Implementing this sliding window counter in a Node.js middleware involves initializing a Map to track the state, calculating the estimated request count using the sliding weight formula, and comparing it with the allowed limit.

If the estimated requests exceed the limit, the request is denied; otherwise, the current count is incremented, and the record is updated.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

When Python is Too Slow

Python is a perfect language for Agile development, where requirements might change on the go. Especially if you are in a startup business, you will need to experiment and change things fast.

  • Python's interpreted nature may lack performance for certain tasks
  • Rust bindings create binary code that can be integrated with Python
  • Rust bindings can speed up processing large CSV files by 4.3x

About Me: Afee Muhammod Wafy

Hello world! 👋 I'm Afee Muhammod Wafy , though most people know me simply as Wafy . I am a science student and self-taught web developer from Rangpur, Bangladesh.

  • Wafy is a science student and self-taught web developer from Rangpur, Bangladesh.
  • Passion for technology driven by curiosity and fundamental understanding.
  • Shares journey and insights on dev.to journal about balancing learning methods.

More from Sunday 23 August →