Forum Discussion
iRule syntax - need help with conditional statement
Actually, here's what we're trying to do Kevin. We are trying to find the best approach to mitigate a HULK HTTP Denial of Service attack. It seems like this type of DoS attack has some unique characteristics that may or may not be covered by the DoS profile properties in the ASM. From what I have gathered, this particular type of attack generates unique requests by changing the user agent, the referrer, and the keep alive time. Perhaps you already know more about this. We were using a WAF from another provider that constructed the rule as follows:
HULK Attack CUSTOM-HULK-DOS-TOOL-v1 609634 %(WAF_CUSTOM_R609634_DENY) 403
And what we are trying to figure out is if this will require a custom irule, if there is a signature that will address this, or can this be addressed with the DoS profile parameters within a DoS profile.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com