Skip to main content

SID-ACCESS-02 — Rate Limiting and Brute-Force Protection

PropertyValue
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupAccess Control

Description

Per-identifier sliding window rate limiting with configurable burst and lockout after threshold. Prevents brute-force authentication attacks. WebSocket sessions limited to 3 concurrent pending flows (DoS protection).

Components

Source References

Framework Requirements

EUDI Security Requirements: WUH-8.3.1-Sec-02, WUH-8.3.2-Sec-01

FitCEM Wallet Instance: FIT-DS-09

ISO 27001 Annex A: A.5.15

OWASP ASVS 4.0.3 Level 3: V2.2, V11.1