Too long tolerance-window
Hello community,
A friend of mine and I are playing the game "Guess what is my tolerance-window". I am trying to recognize all the DoS thresholds of his SBC by sending some signaling against it and analyzing its behavior. I have detected that his untrusted-signaling-threshold is 30 and deny-period is 120, because he becomes silent for 120 seconds on every my 31th sip request.To get to know his tolerance-window I am sending requests with different interval (1 sec, 10 sec, 30 sec, 60 sec). Since he keeps blocking me even If I send 1 request per minute, I can conclude that his tolerance-window is at least 15 minutes (30 request X 60 seconds / 2 = 900 seconds). I assume that his SBC has to keep the DoS counters active for each host:port combination at least for 15 minutes instead of default 30 seconds and this is not good. What