My first step in prank (TDoS) prevention
Hi everybody,
I prepared some LRT based solution which allow you to stop "prank" (mr. McNeil called it TDoS attack) from remote trusted SA. In my case this "prank" looks like enormous number of null duration call. Only one criterion could be used in this case - Calling Party Number. With such a policy configuration SBC forwards to the core realm INVITEs with FROM field value starts from "3", but INVITE with FROM field value = 3130066 will not be forwarded to the core, and SBC will send a response 604 to the pranker-initiator. Maybe it will be helpfull.
Here is local-policy:
local-policy
from-address *