Slow Loris Attack - Computerphile

Denial of service usually relies on a flood of data. Slow Loris takes a more elegant approach, and almost bores a server to death. Dr Mike Pound explains.
Mordhaussays...

No, and that is a method to combat Slow Loris. You can also raise the number of concurrent connections, decrease the timeout on connection response, setting up reverse proxies, and other methods in a similar fashion.

The problem is that you can also modify Slow Loris to work around those methods. The only certain way to block it is to use a webserver software that is not affected by Slow Loris, but then you can encounter other difficulties.

Like he said, for large companies that are prepared, Slow Loris is not nearly as effective. But for smaller web sites or for shoddily put together ones (a LOT of government sites), Slow Loris is a nasty DOS attack.

Baristansaid:

Is it really that hard to detect 200 open sockets from the same IP addr?

Send this Article to a Friend



Separate multiple emails with a comma (,); limit 5 recipients






Your email has been sent successfully!

Manage this Video in Your Playlists




notify when someone comments
X

This website uses cookies.

This website uses cookies to improve user experience. By using this website you consent to all cookies in accordance with our Privacy Policy.

I agree
  
Learn More