AS24-W1-000590 - The Apache web server must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.

Information

Apache web server can limit the ability of the web server being used in a DoS attack through several methods. The methods employed will depend upon the hosted applications and their resource needs for proper operation.

A DoS can occur when the Apache web server is so overwhelmed that it can no longer respond to additional requests. A web server not properly tuned may become overwhelmed and cause a DoS condition even with expected traffic from users.

To avoid a DoS, the Apache web server must be tuned to handle the expected traffic for the hosted applications.

Satisfies: SRG-APP-000246-WSR-000149, SRG-APP-000435-WSR-000148

Solution

Review the <'INSTALLED PATH'>\conf\httpd.conf file.

Add or modify the 'Timeout' directive in the Apache configuration to have a value of '60' seconds or less.

'Timeout 60'

Restart the Apache service.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apache_Server_2-4_Windows_Y26M04_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, 800-53|SC-5(1), CAT|II, CCI|CCI-001094, CCI|CCI-002385, Rule-ID|SV-214338r1192947_rule, STIG-ID|AS24-W1-000590, STIG-Legacy|SV-102515, STIG-Legacy|V-92427, Vuln-ID|V-214338

Plugin: Windows

Control ID: d1825534d2fc9c28a5b6c554db897e0b13124a1ab32f4696e9f9a7ad43583e6e