Forum Discussion
InfoSec_38553
Nov 26, 2011Nimbostratus
ASM DoS attack - Latency options
Hi all,Latency-based options in ASM.There is Suspicious Criteria, IP Detection Criteria and URL Detection Criteria.ASM will check for these three options and the following is the possible cases:1. Suspicious Criteria result is positive then check for IP Detection Criteria if it is positive then it considered the request as DoS.2. Suspicious Criteria result is positive then check for IP Detection Criteria if it
is negative then it check for URL Detection if it is positive then it will considered the request as DoS.3. Suspicious Criteria result is positive then check for IP Detection Criteria if it
is negative then it check for URL Detection if it is negative then it will permit the request and not alert as DoS.
I want to make sure if I'm understanding well
==============
- Latency-base always check for Suspicious Criteria first.
- If one of "Suspicious Criteria" detected and not select any of "Prevention Policy" options ASM just alert and not block any request.
Please tell me if I'm right or not.
Thank you all.
- jwham20NimbostratusFor Latency Based Dos Protection, an attack needs to be suspicious first, before the detection criteria is applied. So what
- InfoSec_38553NimbostratusHi josh,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects