VCLD-67-000022 - VAMI must prevent hosted applications from exhausting system resources.

Information

Most of the attention to denial-of-service (DoS) attacks focuses on ensuring that systems and applications are not victims of these attacks. However, these systems and applications must also be secured against use to launch such an attack against others.

A variety of technologies exist to limit or, in some cases, eliminate the effects of DoS attacks. Limiting system resources that are allocated to any user to a bare minimum may also reduce the ability of users to launch some DoS attacks.

One DoS mitigation is to prevent VAMI from keeping idle connections open for too long.

Solution

Navigate to and open /opt/vmware/etc/lighttpd/lighttpd.conf file.

Add or reconfigure the following value:

server.max-keep-alive-idle = 30

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-239730r879587_rule, STIG-ID|VCLD-67-000022, Vuln-ID|V-239730

Plugin: Unix

Control ID: c1545759256f8bbafe9a8e455de7f71daefa66c900d24d6985147c8bb87eafa6