Services/KeyExchange: Difference between revisions

Jump to navigation Jump to search
Line 348: Line 348:


== Security Logging & Defense ==
== Security Logging & Defense ==
===DOS Defense===
===Channel Flood DOS Defense===
* Least Recently Used (LRU) approach for monitoring IP addresses issuing frequent requests
* Least Recently Used (LRU) approach for monitoring IP addresses issuing frequent requests
** Configurable threshold for adding IP address to Blacklist/Penalty Box
** Configurable threshold for adding IP address to Blacklist/Penalty Box
** Configurable time-out for IP addresses added to Blacklist/Penalty Box
** Configurable time-out for IP addresses added to Blacklist/Penalty Box
** Concern - NAT'ed IP address used by multiple users
** Concern - NAT'ed IP address used by multiple users
=== TearDown DOS Defense ===
=== TearDown DOS Defense ===
* Tear down requires valid channel and valid x-keyexchange-id value
* Tear down requires valid channel and valid x-keyexchange-id value
Confirmed users
491

edits

Navigation menu