- Practical Network Scanning
- Ajay Singh Chauhan
- 196字
- 2022-07-12 10:43:08
Low-rate attacks
Low-rate attacks are focused on bringing a target down quietly. This is very different to high rate brute-force attacks. These attacks leave connections open on the target by creating a relatively low number of connections over a period of time and leaving those sessions open for as long as possible. A famous example of these types of attacks is the Slowloris tool, which allows an attacker to take down a victim's web server with minimal bandwidth requirements and without launching numerous connections at the same time.
Slowloris is an application layer (Layer-7) DDoS attack which operates by utilizing valid partial HTTP requests. The attacker sends HTTP headers with opening connections to a targeted web server and then keeps those connections open for as long as possible, but never completes a request. To avoid connection timeout, the attacker periodically sends another set of partial request headers to the target in order to keep the request alive. This ultimately overflows the maximum concurrent connection pool, and leads to denial of service for subsequent connections from legitimate users.
Mitigation:
- Increase server availability
- Rate limit incoming requests
- Limit the number of connections coming from one IP address.
- 白話網(wǎng)絡(luò)安全2:網(wǎng)安戰(zhàn)略篇
- SASE原理、架構(gòu)與實(shí)踐
- Metasploit Penetration Testing Cookbook(Third Edition)
- Practical Network Scanning
- 工業(yè)控制網(wǎng)絡(luò)安全技術(shù)
- 移動(dòng)APT:威脅情報(bào)分析與數(shù)據(jù)防護(hù)
- Applied Network Security
- API安全技術(shù)與實(shí)戰(zhàn)
- 物聯(lián)網(wǎng)安全滲透測(cè)試技術(shù)
- Web代碼安全漏洞深度剖析
- 云計(jì)算安全技術(shù)與應(yīng)用
- 黑客攻防與電腦安全從新手到高手(超值版)
- 信息組織
- CTF網(wǎng)絡(luò)安全競(jìng)賽入門教程
- CCNA Security 210-260 Certification Guide