A low and slow attack is a DDoS attack that aims to stop a web service using extremely slow HTTP or TCP traffic.
After reading this article you will be able to:
Related Content
R U Dead Yet? (R.U.D.Y.)
Slowloris attack
Web application firewall (WAF)
Ping (ICMP) flood attack
How to DDoS | DoS and DDoS attack tools
Subscribe to theNET, Cloudflare's monthly recap of the Internet's most popular insights!
Copy article link
A low and slow attack is a type of DoS or DDoS attack that relies on a small stream of very slow traffic targeting application or server resources. Unlike more traditional brute-force attacks, low and slow attacks require very little bandwidth and can be hard to mitigate, as they generate traffic that is very difficult to distinguish from normal traffic. While large-scale DDoS attacks are likely to be noticed quickly, low and slow attacks can go on undetected for long periods of time, all while denying or slowing service to real users.
Because they do not require a lot of resources to pull off, low and slow attacks can be successfully launched using a single computer, as opposed to more distributed attacks that may require a botnet. Two of the most popular tools for launching a low and slow attack are called Slowloris and R.U.D.Y.
Low and slow attacks target thread-based web servers with the aim of tying up every thread with slow requests, thereby preventing genuine users from accessing the service. This is accomplished by transmitting data very slowly, but just fast enough to prevent the server from timing out.
Think of a 4-lane bridge with a tollbooth for each lane. Drivers pull up to the tollbooth, hand over a bill or a handful of coins, and then drive across the bridge, opening up the lane for the next driver. Now imagine four drivers showing up at once and occupying every open lane while they each slowly hand pennies over to the tollbooth operator, one coin at a time, clogging up all available lanes for hours and preventing other drivers from getting through. This incredibly frustrating scenario is very similar to how a low and slow attack works.
Attackers can use HTTP headers, HTTP POST requests, or TCP traffic to carry out low and slow attacks. Here are 3 common attack examples:
The rate detection techniques used to identify and stop traditional DDoS attacks will not pick up on a low and slow attack, since they look like normal traffic. The best shot at detecting them is careful monitoring and logging of server resource usage combined with behavioral analysis. Compare traffic and user behavior during normal times to traffic and user behavior during the potential attack period.
If servers are performing slowly or crashing and a low and slow attack is suspected, one sign of such an attack is that normal user processes take much longer. If a user action (such as filling out a form) typically takes a few seconds but is instead taking minutes or hours, occupying far more server resources than normal, a low and slow attack may be the cause.
Once a low and slow attack is detected, mitigation is another issue.
One way to mitigate a low and slow attack is to upgrade your server availability; the more connections your server can simultaneously maintain, the more difficult it will be for an attack to clog your server. The problem with this approach is that an attacker can attempt to scale their attack to meet your server’s availability.
Another solution is reverse proxy-based protection, which will mitigate low and slow attacks before they ever reach your origin server. Learn about how Cloudflare’s cloud-based DDoS protection can mitigate low and slow attacks.
不什么思什么 | 花胶是鱼的什么部位 | 为什么会有高血压 | 黄体酮低吃什么补得快 | 孕妇便秘吃什么 |
什么的长城 | gap是什么品牌 | 胃不好适合吃什么水果 | 还有什么寓言故事 | 转奶是什么意思 |
血压高压高低压正常是什么原因 | 内分泌失调是什么原因 | 桥本是什么意思 | pt是什么时间 | 什么叫流年 |
血压低吃什么中成药 | 狗狗咳嗽吃什么药 | 艾滋病脖子有什么症状 | homie是什么意思 | 得了狂犬病有什么症状 |
雪白雪白的什么hcv9jop1ns0r.cn | 蓝矾对人有什么危害hcv8jop7ns3r.cn | 做肠镜检查需要提前做什么准备hcv8jop1ns5r.cn | 德国什么东西值得买hcv9jop1ns5r.cn | 豆芽炒什么好吃hcv9jop3ns5r.cn |
狗狗拉虫子又细又长吃什么药hcv8jop4ns0r.cn | 当驾校教练需要什么条件hcv8jop7ns2r.cn | 胆囊切除后对身体有什么影响hcv7jop9ns7r.cn | 苹果跟什么榨汁好喝hcv9jop5ns6r.cn | 佛舍利到底是什么hcv8jop1ns3r.cn |
器质性心脏病是什么意思hcv9jop2ns1r.cn | 补体c3偏低是什么意思hcv7jop9ns3r.cn | 嗯嗯嗯是什么意思hcv8jop7ns6r.cn | 高颜值是什么意思96micro.com | pef是什么意思hcv8jop2ns5r.cn |
手指甲月牙代表什么hcv8jop9ns7r.cn | 清朝什么时候建立hcv8jop7ns2r.cn | 为什么都开头孢不开阿莫西林hcv9jop7ns4r.cn | 低血压去药店买什么药shenchushe.com | 孕妇吸二手烟对胎儿有什么影响hcv8jop6ns3r.cn |