Forum Discussion
TTrautman_94620
Nimbostratus
Jun 19, 2009Slowloris
Does any know how ASM would handle this recently posted Denial of Service attack:
http://ha.ckers.org/slowloris/
The concept is the client hogs sockets by slowly tricklin...
Benjamin_9036
Jul 15, 2009Historic F5 Account
This shouldn't happen in most circumstances. The principal behind Slowloris to remain fairy low profile on the wire. It would only take ~600 connections and a very negligible amount of bandwidth to affect one of the threaded web servers that is vulnerable to this which should be little more than a drop in the proverbial bucket for the ASM devices. Even when the volume is increased, nearing more of a 'DoS-by-volume' than a 'Slowloris' type attack, the network layer on the ASM and LTM use a handful of methods to control this type of attack (SynCookies, aggressive connection reaping, et cetera). Though when the volume is increased, this truly becomes a traditional DoS attack, using simple volume in an attempt to overwhelm, rather than the more targeted and light-on-the-wire approach that the 'Slowloris' method uses.
// Ben
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects