官术网_书友最值得收藏!

Low-rate attacks

Low-rate attacks are focused on bringing a target down quietly. This is very different to high rate brute-force attacks. These attacks leave connections open on the target by creating a relatively low number of connections over a period of time and leaving those sessions open for as long as possible. A famous example of these types of attacks is the Slowloris tool, which allows an attacker to take down a victim's web server with minimal bandwidth requirements and without launching numerous connections at the same time.

Slowloris is an application layer (Layer-7) DDoS attack which operates by utilizing valid partial HTTP requests. The attacker sends HTTP headers with opening connections to a targeted web server and then keeps those connections open for as long as possible, but never completes a request. To avoid connection timeout, the attacker periodically sends another set of partial request headers to the target in order to keep the request alive. This ultimately overflows the maximum concurrent connection pool, and leads to denial of service for subsequent connections from legitimate users.

Mitigation:

  • Increase server availability
  • Rate limit incoming requests
  • Limit the number of connections coming from one IP address.
主站蜘蛛池模板: 沐川县| 龙陵县| 新源县| 宽甸| 美姑县| 天长市| 常德市| 玛纳斯县| 科尔| 太湖县| 万宁市| 额济纳旗| 海丰县| 娄烦县| 广丰县| 纳雍县| 泗洪县| 虞城县| 长宁县| 广元市| 曲松县| 金坛市| 奉贤区| 建湖县| 黄山市| 长丰县| 遂川县| 宝丰县| 南雄市| 南昌市| 万荣县| 谢通门县| 渝北区| 嘉祥县| 临汾市| 六枝特区| 稻城县| 平罗县| 西盟| 新宾| 林芝县|