Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Protecting Against DDoS attacks: Is Mod_Security and the OWASP rule set adequate? [closed]

Is mod_sec and the OWASP rule set adequate to protect against DDoS and DoS attacks or would you recommend taking additional steps, e.g. blocking suspicious IP addresses which have been identified by mod_sec using iptables?

Would you recommend activating mod_evasive in addition to mod_sec?

What about ShoreWall and CSFirewall?

Thank you!

like image 669
AlexR Avatar asked Dec 05 '25 19:12

AlexR


1 Answers

mod_sec only provides "rate-limiting", that can offer a degree of DOS protection, when the attack originates from same set of IP addresses. It can deny/drop connections, when let's say there are more than, say 20 requests from the same IP. It would not offer protection from DDoS, where compromised command and control hosts continue slow paced attacks spanning over days.

On your second question: I do not have much insight into mod_evasive.

like image 69
Manish Maheshwari Avatar answered Dec 08 '25 13:12

Manish Maheshwari



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!