UWIT-IAM / uw-idp-custom

Local IdP configuration and etc customizations
0 stars 0 forks source link

Better detection of heavy traffic from single IP address (e.g. DOS attack) #17

Open JimTomlinson-UW opened 1 year ago

JimTomlinson-UW commented 1 year ago

INC2561130 pointed out a vulnerability we have to misbehaving client applications. The logfile on iamproxy02 was filling the disk due to ~40 requests/second from a single IP address. While that situation resolved itself (thanks to efforts on EricH's part, and the client spontaneously stopping its behavior), to quote EricH: "Detection of wayward or unhealthy Idp clients such as this one would be a good monitoring improvement. Even a connection rate alert could help identify emerging situations."