官术网_书友最值得收藏!

Low-rate attacks

Low-rate attacks are focused on bringing a target down quietly. This is very different to high rate brute-force attacks. These attacks leave connections open on the target by creating a relatively low number of connections over a period of time and leaving those sessions open for as long as possible. A famous example of these types of attacks is the Slowloris tool, which allows an attacker to take down a victim's web server with minimal bandwidth requirements and without launching numerous connections at the same time.

Slowloris is an application layer (Layer-7) DDoS attack which operates by utilizing valid partial HTTP requests. The attacker sends HTTP headers with opening connections to a targeted web server and then keeps those connections open for as long as possible, but never completes a request. To avoid connection timeout, the attacker periodically sends another set of partial request headers to the target in order to keep the request alive. This ultimately overflows the maximum concurrent connection pool, and leads to denial of service for subsequent connections from legitimate users.

Mitigation:

  • Increase server availability
  • Rate limit incoming requests
  • Limit the number of connections coming from one IP address.
主站蜘蛛池模板: 开鲁县| 扶绥县| 扎鲁特旗| 安达市| 东乌珠穆沁旗| 远安县| 久治县| 商河县| 清原| 定南县| 航空| 青田县| 库尔勒市| 江陵县| 大理市| 铜川市| 秀山| 吉林市| 嘉义县| 视频| 山西省| 宁城县| 资溪县| 松原市| 杨浦区| 绥芬河市| 南汇区| 亚东县| 洞口县| 嘉鱼县| 汶上县| 武陟县| 霍林郭勒市| 崇礼县| 黄大仙区| 株洲市| 开鲁县| 驻马店市| 汤阴县| 凤凰县| 房山区|