Protections against DoS attacks must be implemented.

From Application Security and Development Security Technical Implementation Guide

Part of ASDV-PL-003320

Associated with: CCI-002386

SV-85035r1_rule Protections against DoS attacks must be implemented.

Vulnerability discussion

Known DoS threats documented in the threat model should be mitigated, to prevent DoS type attacks.

Check content

Ask the application representative for the threat model document. Examine the threat model document and determine if DoS attacks are specified as a threat. If there are no DoS threats identified in the threat model, the requirement is not applicable. Verify the mitigations provided for DoS attacks are implemented from the threat model. If mitigations for DoS attacks are identified in the threat model but are not implemented, this is a finding.

Fix text

Implement mitigations from the threat model for DOS attacks.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer