HTTP Time Bandit

HTTP Time Bandit

BruCON Security Conference via YouTube Direct link

References

24 of 24

24 of 24

References

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

HTTP Time Bandit

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 Who?
  3. 3 DOS Clasification
  4. 4 Classic Application Layer DOS/DDOS
  5. 5 Get Flooding With Spice
  6. 6 The Proposed Method
  7. 7 Lies, Dirty Lies and Statistics
  8. 8 Using Statistics to Normalize the Data Mean as the measure of central tendency • Calculate the mean of all resource download speeds • Calculate the means of each resource download
  9. 9 Speed Distribution
  10. 10 Demo
  11. 11 Attack Like Stage of Testing Measurement of service degradation while doing a hard test for narrowing down the choice of links
  12. 12 Load Balancers
  13. 13 Commercial Protection Services • Few players using limiters for
  14. 14 Using the Tool for Good Identify/Fix resource hogs o Use our tool for this
  15. 15 Playing with Apache Configs
  16. 16 mod_security
  17. 17 mod_limitipconn
  18. 18 mod_qos
  19. 19 mod_bwshare Accepts or rejects HTTP requests from each client IP address, based on thresholds set by past traffic from a particular IP address[8]
  20. 20 mod_evasive
  21. 21 Conflicts with Slow* Attacks
  22. 22 mod_httpbl
  23. 23 Back to the Future
  24. 24 References

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.