• Home
  • Download
  • Links
  • Photoplog
  • Blowfish Secret
  • Base64
  • Wordpress Salt
  • Contact
  • ROM
  • Skins
  • VIP
  • Tutorial
Wckediden - Mobile Tricks and Tweaks Community  

Go Back   Wckediden - Mobile Tricks and Tweaks Community > Community Software > Webmaster Software (Windows System Only 64bit) > Apache Server
Reload this Page [INFO] Mitigating Denial of Service Attacks with mod_qos
Wckediden
Register Forum Rules FAQ Community Today's Posts Search

Notices
Under Construction

WckedIDen Forum Renovations

WckedIDen is currently undergoing forum structure renovations. During this process, you may experience intermittent errors, unavailable pages, or temporary service interruptions.

Please be patient while we work to improve the forum. We appreciate your understanding and continued support.


Community Links
Social Groups
Pictures & Albums
Members List
Meet Our Staff
Search Forums
 
Tag Search
Advanced Search
Search Downloads
Advanced Search
Search Links
Advanced Search
Find All Thanked Posts



Post New ThreadReply
 
Thread Tools Search this Thread
  #1  
Old 07-13-2024, 01:33 AM
wcked's Avatar
wcked wcked is offline   Thread Starter  
Supporter/Designer
Mobile Model: Google Pixel 10 Pro
Mobile Carrier: Metro PCS
Mobile OS: Android

  usa
 
Join Date: November 8th, 2005
Location: North Philadelphia
Posts: 10,398
Downloads: 18
Uploads: 181
wcked has disabled reputation


View wcked's Profile   Edit Options Edit Profile Picture View wcked's Photo Album Add wcked's to Your Contacts Show Groups Edit Avatar Subscribed Threads Private Messages
Default Mitigating Denial of Service Attacks with mod_qos

Denial of service (DoS) attacks, whereby an attacker or group of attackers attempts to make a service on the Internet unavailable, are a growing threat. Chief among the rising DoS threats are those linked to a ransom, where the attackers threaten to attack an organisationÃÃ*’ ¢ÃƒÂ¢Ã¢â‚¬Å ¡Ã‚¬Ã¢â €žÂ¢s systems unless they make a large payment to the attackers.


If your organisation is targeted in such a ransom-based DoS attack, the evidence is clear ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ do not pay the ransom. There are two major reasons why one should never pay such a ransom ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ the attackers could continue to demand more ransom payments in the future, knowing that you are a target that will pay. The other major reason you should never pay a ransom to avoid a DoS attack is that there are many measures you can put in place to mitigate or prevent such attacks entirely. We discuss one such mitigation measure in this concise article ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ blocking, banning, and throttling abusive traffic with mod_qos for Apache.


mod_qos is billed by its author as a quality of service module, meaning it is designed to prioritise requests and traffic to ensure that the most important traffic can get through with good performance and speed.


The documentation lists a number of ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“control mechanismsÃÃ*’ ¢ÃƒÆ’¢â€Š¡Ãƒâ€šÃ‚¬Ãƒâ€šÃ ‚ that the module is capable of facilitating:


“ Quote ”

  • The maximum number of concurrent requests to a location/resource (URL) or virtual host.
  • Limitation of the bandwidth such as the maximum allowed number of requests per second to an URL or the maximum/minimum of downloaded kbytes per second.
  • Limits the number of request events per second (special request conditions).
  • Limits the number of request events within a defined period of time.
  • It can also detect very important persons (VIP) which may access the web server without or with fewer restrictions.
  • Generic request line and header filter to deny unauthorized operations.
  • Request body data limitation and filtering (requires mod_parp ).
  • Limits the number of request events for individual clients (IP).
  • Limitations on the TCP connection level, e.g., the maximum number of allowed connections from a single IP source address or dynamic keep-alive control.
  • Prefers known IP addresses when server runs out of free TCP connections.

In the example to follow, we will configure a number of the above control mechanisms, particularly those that are most helpful with public web application use cases.


To keep this article brief, we will not cover installation and configuration of Apache itself, or set up of Apache virtual hosts (sites). These instructions assume the server is running Apache HTTP Server on ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“enterprise LinuxÃÃ*’Ã‚Â¢à ƒÂ¢Ã¢â‚¬Å¡à ‚Â¬Ãƒâ€šÃ†šÃ‚ (Red Hat, Oracle, CentOS, AlmaLinux, Rocky, etc.), but they can easily be adapted for other Linux distributions like Ubuntu, Debian, or SuSE.


[HEADING=1]First, install mod_qos.[/HEADING]

In enterprise Linux distributions, mod_qos is in the EPEL repositories. So if that is not already set up on the machine in question, set it up like so:

Code

yum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm
Then install the mod_qos package from EPEL:

Code

yum install mod_qos

[HEADING=2]Edit the configuration file[/HEADING]

Next, edit /etc/httpd/conf.modules.d/10-mod_qos.conf in your favourite text editor, and paste the following:

Code

LoadModule qos_module modules/mod_qos.so

# mod_qos DoS Mitigation

# HTTP response code to send to clients that breach mod_qos DoS mitigation rules
QS_ErrorResponseCode 429

# IP addresses excluded from request limits (office IP address)
QS_ClientEventBlockExcludeIP 9.9.9.9

# Maximum number of clients that mod_qos can track at any one time (not itself a limit on maximum clients allowed).
QS_ClientEntries 200000

# Envrionment variables
SetEnvIf Remote_Host "(.*)" QS_EventRequest=$1
SetEnvIf Remote_Host "(.*)" QS_Event=$1
SetEnvIf Remote_Host "(.*)" QS_Block=$1

# Maximum *concurrent* requests allowed per IP address
QS_ClientEventRequestLimit 150

# Maximum requests allowed to / per second, per IP address
QS_ClientEventPerSecLimit 150

# Maximum requests allowed to / per ip address, per x seconds (number of requests, number of seconds)
QS_ClientEventBlockCount 2000 120

# IP addresses excluded from connection limits (office IP address)
QS_SrvMaxConnExcludeIP 9.9.9.9

# Maximum number of connections allowed per IP, to server across all virtual hosts
QS_SrvMaxConnPerIP 12

You will likely need to add to and adjust this example configuration, but it is a sane place to start. The IP address IÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€š ¬Å¾Ã‚¢ve set for QS_ClientEventBlockExcludeIP is actually the address for Quad9, a free public DNS service, which we are only using as a place-holder in the example.



[HEADING=1]Configuration explanation[/HEADING]

The number of options for mod_qos is massive, and one can develop quite sophisticated defenses with it alone. The developer really deserves credit and our gratitude for writing such comprehensive and effective software. Given there are so very many options, we are covering an essential set of features here. See the complete documentation for many more options and details.


LoadModule qos_module modules/mod_qos.so simply loads the mod_qos module when Apache starts. This is all that is part of the default configuration of mod_qos. When you edit 10-mod_qos.conf for the first time, you will likely see this line already present.


QS_ErrorResponseCode is the HTTP status code sent back to offending clients that breach the rules defined by mod_qos. In the example above, IÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â€š ¬Å¾Ã‚¢ve set that to 429 ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“too many requestsÃÃ*’¢ â‚ ¬ÂÃ⠀šÃ‚. You can set this response to anything at all, but 429 is probably the correct response for most use cases. Other 400-level status codes may apply, depending on what sort of abusive traffic your systems are most likely to be blocking. Fun fact: Twitter used to use the unofficial status code of 420 ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“enhance your calmÃÃ*’¢Ã ƒÂ¢Ã¢â‚¬Å¡Ã ‚¬Ã‚Ɲ, to tell clients they were making too many requests in a given period of time (they now apparently use 429). You are, of course, welcome to use 420 (or, again, any status code) as well. ÃÃ*â€™Ãƒâ€šÃ‚Â°ÃƒÆ Ã¢â‚¬Â¦Ãƒâ€šÃ‚Â¸ÃƒÆ’Ã‚ ¢Ã¢â‚¬Å¾Ã‚à ¢ÃƒÂ¢Ã¢â€šà ¬Ã…Â¡ Regardless, I suggest using some 400-level code, because ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“too many requestsÃÃ*’¢ â‚ ¬ÂÃ⠀šÃ‚ is definitely a client-caused issue, and client-side issues are what 400 codes are for.


QS_ClientEventBlockExcludeIP is where you may put a space delimited list of IP addresses that are excluded from ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“client eventÃÃ*’Ã‚Â¢à ƒÂ¢Ã¢â‚¬Å¡à ‚Â¬Ãƒâ€šÃ†šÃ‚ rules, such as rules that limit how many requests a given host can make. This means that hosts listed in this parameter can make as many requests to the sites as they want, without being throttled, denied, or blocked. We typically put the IP addresses of our clientsÃÃ*’¢ ƒÆ’¢â€š ƒâ€šÃ‚¬ÃƒÂ¢Ã¢â €šÂ¬Ã…¾Ã‚¢ offices in this list, because many users are likely connecting from those IP addresses due to network address translation (NAT) ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ an entire office with many people in it often has only one IP address.


QS_ClientEntries sets the size of the list of clients that mod_qos may keep track of at any given time. This number can be set as high as you would like. Just bear in mind that the list does consume memory, albeit not a tonne of memory. Each entry in the QS_ClientEntries list consumes 150 bytes on a 64 bit operating system. I often set this parameter to ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¹Ãƒâ€¦Ã â‚¬Å“1000000ÃÃ*’Ã⠚¢Ã¢ââ‚ ¬Ã…¡Ã‚¬Ã¢ „ ¢ (one million), which consumes up to 150 megabytes of memory. The values stored in QS_ClientEntries survive a graceful restart (systemctl reload httpd), but not a ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“normalÃÃ*’ ƒâ€šÃ‚¢ÃƒÂ¢Ã¢â €šÂ¬Ã…¡Ã‚¬Ãà ¢â‚¬Å¡Ãƒâ€šÃ‚ restart or stop / start operation.


This next bit, where we set some environment variables, took a bit of thinking to work out. It employs ApacheÃÃ*’¢à ƒÆ’¢â€šà ƒâ€šÃ‚¬ÃƒÂ¢Ã¢â⠀šÂ¬Ã…¾Ã‚¢s own environment variable functions, which are incredibly useful. LetÃÃ*’¢Ã ’¢â€šÃ €šÃ‚¬ÃƒÂ¢Ã¢â†šÂ¬Ã…¾Ã‚¢s break down the first environment variable definition in the example.


SetEnvIf Remote_Host "(.)" QS_EventRequest=$1: Here, ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¹Ãƒâ€¦Ã â‚¬Å“SetEnvIfÃÃ*’Ã⠚¢Ã¢ââ‚ ¬Å¡Ã‚¬Ã â€žÂ ¢ defines an Apache environment variable, ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¹Ãƒâ€¦Ã â‚¬Å“Remote_HostÃÃ*’à ‚¢Ã¢ââ⠚¬Å¡Ã‚¬Ã ¢Ã¢â‚¬Å¾Ã‚à ¢ is the header we are selecting for (and stands for the client IP address), the ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“(.)ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Å¡Ãƒâ€šÃ ‚ is a regular expression which basically means ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã¢â‚¬Â¦ÃƒÂ¢Ã¢â €šÂ¬Ã…“match anythingÃÃ*’¢ â‚ ¬ÂÃ⠀šÃ‚, and QA_EventRequest is the variable name. As you can see, the other two environment variable definitions follow the same syntax.


QS_ClientEventRequestLimit sets the maximum concurrent requests per client.


QS_ClientEventPerSecLimit sets the maximum number of requests allowed per client, per second.


QS_ClientEventBlockCount sets the maximum number of requests allowed per client per x number of seconds. In the example, we set a limit of 2000 requests per client IP address, over 120 seconds (two minutes, of course). We set this limit, as well as the QA_ClientEventRequestLimit, because QA_ClientEventRequestLimit can not be very high in many cases ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚ thatÃÃ*’¢Ã ƒÂ¢Ã¢â‚¬Å¡Ã ‚¬Ã¢ââ⠚¬Å¾Ã‚¢s because we have to allow clients to make somewhat larger numbers of requests in bursts. At the same time, making more than 2000 requests in a two minute time span would be very unlikely to be due to legitimate use in most cases. So we set this as a criterion for a ban.


QS_SrvMaxConnExcludeIP sets which hosts are excluded from connection limit rules.


QS_SrvMaxConnPerIP sets the maximum number of connections allowed per client IP address. Our example puts that at 12, which is more connections than what all modern browsers would open at any single moment in time.


Other rules must be set per virtual host. Most or all of the rules used in our example above must be defined outside of a virtual host directive.



With that, one already has very good defenses against DoS attacks. A lot more can be done to make for more complete protection against such threats, however. Other lines of defense include network firewalls, web application firewalls, web server configuration parameters, and application-level parameters.


Did you like this post on mod_qos? Are you looking for more fabulous articles on amazing things that can be done with Apache? Then check out this article on load balancing with Apache!ÃÃ*â€™Ãƒâ€šÃ‚Â¢ÃƒÆ Ã‚Â¢ÃƒÂ¢Ã¢â€šÂ¬Ã…Â¡Ãƒâ šÃ‚Â¬ÃƒÆ’Ã‚Â¢ÃƒÂ¢Ã¢â‚¬ ¡Ã‚¬Ã‚¹

Reply With Quote
wcked
View Public Profile
Visit wcked's homepage!
Find all posts by wcked
Post New ThreadReply

« Previous Thread | Next Thread »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Thread Tools
Show Printable Version Show Printable Version
Search this Thread

Advanced Search
Donate Via PayPal
Amount:
Enter Short Message:
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[NEWS] Twitter crippled by denial-of-service attack wcked Bulletin News 9 08-07-2009 05:58 AM
Site Disclamier And Term Of Service wcked Bulletin Announcements 1 08-07-2008 01:33 PM
.NET Compact Framework 2.0 Service Pack 2 Redistributable D/\SH WM And PPC Applications 0 07-13-2007 04:48 PM
Court backs FCC exemption of Web phone service wcked Bulletin News 0 03-22-2007 06:07 PM


All times are GMT -4. The time now is 01:11 PM.

Wckediden Community - Archive - Privacy Statement - Terms of Service - Top


Powered by vBulletin® Version 3.8.14
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Template-Modifications by TMS
POWERED BY PHILLYFINESTSERVERSTAT FOR WCKEDIDEN|- NEXTELELITE| - PPCTHEME| - IDENINSIDER