-
Notifications
You must be signed in to change notification settings - Fork 29
Open
Labels
Description
From @bhcrosslake on January 12, 2017 0:35
As a DFSP, I don't want other DFSPs to get a complete list of my user numbers.
This could be possible through a brute force attack on the SPSP Server. To prevent that, the SPSP server should implement a circuit breaker to throttle queries from DFSPs that repeatedly try user numbers that don't exist.
Acceptance Criteria
- 3 bad queries in a row raise an event that can be used for fraud detection. These events can be seen in the operational UI. (# is configurable)
- The event also causes future SPSP queries from that DFSP to be slowed. Responses are not returned for a minute (time is configurable)
- An operator in the operational UI can clear the slowed state
This is a relatively low priority story as it doesn't involve money gain/loss. It may ignored if it is accomplished through the central hub. see #336
Copied from original issue: LevelOneProject/Docs#337