
Oracle SBC Security Guide
Appendix D: DDoS Prevention for Access or Hybrid Environments
Configuration Models:
The settings outlined in this appendix apply to the following configuration models:
Policy Based Realm Bridging Model
Single SIP NAT Hosted in Trusted Network Model
Supported platforms:
Configuration Parameters
The maximum signaling bandwidth per platform should be set to keep the CPU usage below 90%.
The following sections will discuss those “DDoS” parameter pertinent to the scope of this appendix. It’s
important to note: the parameters used to satisfy the requirements and scope of this appendix cannot be
considered to be exhaustive. The parameters used are those which will be modified for this basic
configuration. These parameters are in three configuration areas: Media Manager, Realm Configuration,
and SIP Interface.
DDoS Configuration Parameter Descriptions
Media Manager
The following media-manager parameters have been calculated for each configuration model.
Maximum percentage of allocated total CPU usage
for untrusted traffic (%)
Minimum percentage of allocated total CPU usage
for untrusted traffic (%)
The maximum bandwidth that the SBC can
withstand (bytes/sec)
These parameters are set to values that do not allow a SIP Register flood attack to increase the total CPU
utilization percentage to over 89%. The background trusted traffic must not be adversely affected.
The recommended values for these media-manager parameters for each test scenario are listed by system
model.
Comentarios a estos manuales