Using Statistics to Normalize the Data Mean as the measure of central tendency • Calculate the mean of all resource download speeds • Calculate the means of each resource download
9
Speed Distribution
10
Demo
11
Attack Like Stage of Testing Measurement of service degradation while doing a hard test for narrowing down the choice of links
12
Load Balancers
13
Commercial Protection Services • Few players using limiters for
14
Using the Tool for Good Identify/Fix resource hogs o Use our tool for this
15
Playing with Apache Configs
16
mod_security
17
mod_limitipconn
18
mod_qos
19
mod_bwshare Accepts or rejects HTTP requests from each client IP address, based on thresholds set by past traffic from a particular IP address[8]
20
mod_evasive
21
Conflicts with Slow* Attacks
22
mod_httpbl
23
Back to the Future
24
References
Description:
Explore an in-depth analysis of HTTP-based Denial of Service (DoS) attacks and their countermeasures in this conference talk from BruCON 0x05. Delve into various DoS classifications, including classic application layer attacks and Get Flooding techniques. Learn about a proposed method for normalizing data using statistical analysis, and witness a live demonstration of attack testing and service degradation measurement. Examine the role of load balancers and commercial protection services in mitigating these threats. Discover how to leverage the presented tools for identifying and fixing resource-intensive elements within web applications. Investigate Apache configurations and modules such as mod_security, mod_limitipconn, and mod_qos for enhancing protection against DoS attacks. Gain insights into the conflicts between certain modules and Slow* attacks, and explore future directions in HTTP-based DoS prevention.