f5rocks_86658
Feb 15, 2019Nimbostratus
ASM DoS detection
Does it mean that DoS would be detected if requests per source IP reached to 200 per second? What's the significance of 40 tps here?
Does it mean that DoS would be detected if requests per source IP reached to 200 per second? What's the significance of 40 tps here?
Hi f5rocks,
The ASM DoS feature measures the TPS every 10 seconds and calculates the average for the past hour.
DoS will be detected when an absolute TPS value of 200 is reached, but also when an absolute TPS value of 40 is reached AND an increase of 500% is detected.
Example:
Based on your screenshot DoS will be detected because TPS increased by 700% (> 500%) and absolute value is 600 TPS (> 40 TPS).
Leon
Thanks. But if last TPS is600, doesn't DoS will be detected immediately as it's higher than absolute threshold (200 TPS). My point was if both values come to same TPS rate (i.e increased TPS% or absolute Threshold) so not sure why two conditions are given. Also hope as name suggests these are for single source IP.