Forum Discussion
TTrautman_94620
Nimbostratus
Jun 19, 2009Slowloris
Does any know how ASM would handle this recently posted Denial of Service attack:
http://ha.ckers.org/slowloris/
The concept is the client hogs sockets by slowly tricklin...
Benjamin_9036
Jun 19, 2009Historic F5 Account
Heya,
I spent some time testing this yesterday, in fact. Since the ASM acts as a full proxy, the connections are never opened to the pool members. Watching Slowloris traffic on the wire showed that it consumed threads by sending a POST with a Content-Length that it never fulfilled. Since ASM doesn't open a connection to the servers until it has received, parsed, and approved (based on the security policy), and Slowloris never completes its request the ASM never opens a connection to the servers. Since the point of Slowloris is to not simply DoS by volume (the default number of sockets is only 500), this should probably not cause any problems.
// Ben
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects