atom feed29 messages in ru.sysoev.nginxRe: DDoS protection module suggestion
FromSent OnAttachments
malteNov 2, 2010 7:18 pm 
Weibin YaoNov 2, 2010 7:54 pm 
malteNov 2, 2010 8:21 pm 
pchy...@gmail.comNov 2, 2010 8:57 pm 
malteNov 3, 2010 2:00 pm 
unclepiemanNov 3, 2010 2:14 pm 
Rainer DuffnerNov 3, 2010 2:38 pm 
malteNov 3, 2010 7:22 pm 
malteNov 3, 2010 7:30 pm 
Redd VinyleneNov 4, 2010 1:48 am 
malteNov 4, 2010 12:47 pm 
Weibin YaoNov 4, 2010 7:17 pm 
Payam ChychiNov 4, 2010 9:03 pm 
Weibin YaoNov 4, 2010 10:02 pm 
malteNov 4, 2010 10:58 pm 
Payam ChychiNov 5, 2010 12:29 am 
Weibin YaoNov 5, 2010 2:32 am 
Weibin YaoNov 5, 2010 2:51 am 
EugaiaNov 5, 2010 3:36 am 
姚伟斌Nov 5, 2010 5:47 am 
malteNov 5, 2010 9:10 am 
malteNov 5, 2010 9:15 am 
Payam ChychiNov 5, 2010 10:02 am 
malteNov 5, 2010 2:51 pm 
malteNov 5, 2010 2:52 pm 
姚伟斌Nov 5, 2010 6:44 pm 
ken107Dec 26, 2010 1:48 am 
Weibin YaoDec 26, 2010 6:25 pm 
Waleed G.Mar 25, 2012 10:03 am 
Subject:Re: DDoS protection module suggestion
From:malte (ngin@nginx.us)
Date:Nov 4, 2010 10:58:08 pm
List:ru.sysoev.nginx

Weibin Yao Wrote:

We are facing the similar DDOS situation to you. I'm developing a module which can deny the individual IPs. The module can get the IPs with a POST request from a commander server in the intranet. If you have some suggestions, you can contact to me.

The module will be here: https://github.com/yaoweibin/nginx_limit_access_mo dule, but I need some more days to finish it.

Wonderful! Being able to interrogate the server for a list of bad IPs is an excellent idea, it would allow people to make their own firewall-block scripts etc.

The main suggestion I have is that the module supports this kind of rule: If an IP has requested more than X pages in the last Y seconds, then serve only 503 errors to that IP for the next Z seconds, and use at most W megabytes of RAM for the bad-IP pool.

Posted at Nginx Forum:
http://forum.nginx.org/read.php?2,147105,147863#msg-147863