Welcome! Log In Create A New Profile

Advanced

Re: DDoS protection module suggestion

November 05, 2010 05:52PM
unclepieman Wrote:
-------------------------------------------------------
> Hey Malte,
>
> During a ddos attack, you are sending
> $possible_bad-ip to a different
> server that just sits there and does nothing but
> Captcha. The cost for
> showing a captcha to a host is far less than the
> impact it would have on
> your network/servers.
>
> also on the captcha you can implement cookie
> checks and if the host does
> not become valid say after seeing the page
> $n_times then you can add the
> ip to an acl block list. Layer3-4 blocking cost is
> much less than
> layer7, same goes for if you are taking the threat
> away from your
> production internet facing servers and forcing the
> possible bad hosts go
> through a captcha system.
>
> the last time i setup a network to handle 400mbps
> and 140k connection
> (not packets) a second attack it was with the
> suggestions and topology
> ive described, its worked without issues for me
> but perhaps you are
> seeing something that i have not.

Yeah I'm not saying you are wrong at all. But I can vouch for that it was a decidedly bad idea to block 50k IPs in IPtables like I did, that made all network related activity slower than a dying turtle. And personally, for an IP requesting 50 pages per second, I don't feel bad at all 503:ing them instead of giving them a captcha chance. For a lower intensity captcha I can see how your captcha system would shine though.

I'd love to see a flexible nginx module that can support either approach. And this one that Weibin is working on sounds pretty promising!
Subject Author Posted

DDoS protection module suggestion

malte November 02, 2010 10:19PM

Re: DDoS protection module suggestion

Weibin Yao November 02, 2010 10:58PM

Re: DDoS protection module suggestion

malte November 02, 2010 11:21PM

Re: DDoS protection module suggestion

unclepieman November 03, 2010 12:02AM

Re: DDoS protection module suggestion

malte November 03, 2010 05:00PM

Re: DDoS protection module suggestion

unclepieman November 03, 2010 05:15PM

Re: DDoS protection module suggestion

malte November 03, 2010 10:30PM

Re: DDoS protection module suggestion

Redd Vinylene November 04, 2010 04:52AM

Re: DDoS protection module suggestion

malte November 04, 2010 03:47PM

Re: DDoS protection module suggestion

Weibin Yao November 04, 2010 10:28PM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 12:10AM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 01:08AM

Re: DDoS protection module suggestion

malte November 05, 2010 01:58AM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 03:34AM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 05:56AM

Re: DDoS protection module suggestion

Eugaia November 05, 2010 06:44AM

Re: DDoS protection module suggestion

姚伟斌 November 05, 2010 08:52AM

Re: DDoS protection module suggestion

malte November 05, 2010 12:16PM

Re: DDoS protection module suggestion

姚伟斌 November 05, 2010 09:50PM

Re: DDoS protection module suggestion

malte November 05, 2010 12:11PM

Re: DDoS protection module suggestion

unclepieman November 05, 2010 01:08PM

Re: DDoS protection module suggestion

malte November 05, 2010 05:52PM

Re: DDoS protection module suggestion

malte November 05, 2010 05:53PM

Re: DDoS protection module suggestion

Weibin Yao November 05, 2010 05:42AM

Re: DDoS protection module suggestion

Rainer Duffner November 03, 2010 05:42PM

Re: DDoS protection module suggestion

malte November 03, 2010 10:22PM

Re: DDoS protection module suggestion

ken107 December 26, 2010 04:49AM

Re: DDoS protection module suggestion

Weibin Yao December 26, 2010 09:32PM

Re: DDoS protection module suggestion

Waleed G. March 25, 2012 01:04PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 244
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready