WB-D-2 — VCTM registry query flood (port 8097)
Component: Wallet Backend. Mitigations: Per-tenant rate limit + shared anonymous pool (configurable RPM). Action: Ensure anonymous pool limit is set conservatively in production
| Property | Value |
|---|---|
| Section | Denial of Service |
| Owner | operator |
Mapped Controls
| Control | Title |
|---|---|
| SID-HARD-02 | Input Validation and Injection Prevention |
Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md