FINDING · DEPLOYMENT
Without per-site connection limits, popular decoy hosts risk resource exhaustion (Apache's default cap is 150 simultaneous connections); enforcing an initial limit of 30 concurrent clients per site—coordinated across stations via a central collector—kept the median site load at ~5 simultaneous clients, with the 99th-percentile site peaking at 37 after the limit was raised to 45.
From 2017-frolov-isp-scale — An ISP-Scale Deployment of TapDance · §3.5, §4.3, Figure 9 · 2017 · Free and Open Communications on the Internet
Implications
- Implement a central coordinator that tracks per-decoy-site concurrent user counts across all stations and signals stations to redirect new clients when a site nears its connection limit.
- Apply exponential back-off when a client fails to connect to its chosen decoy site to prevent thundering-herd load spikes from cascading across backup sites.
Tags
Extracted by claude-sonnet-4-6 — review before relying.