Prevent Denial of Service Attacks

In order to reduce the possibility of denial of service (DoS) attacks, Oracle recommends that you configure the “message timeout” parameter for the server. By default, the server waits for 60 seconds to receive the complete message—the timeout duration is set to a high level to accommodate slow connections. You must lower the message timeout parameter to the lowest possible setting.

Another best practice to prevent DoS attacks is to restrict the size of the message (the default is 10MB) and the message timeout (the default is 480 seconds) on external channels. You can also limit the number of sockets allowed for a server by setting the Maximum Open Sockets option on the server configuration page.

Get Oracle WebLogic Server 11g Administration Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.