Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

INFO: Preventing "Slow HTTP" Attacks

Expand / Collapse


This article applies to:

  • WAF 8.0

Question:

  • Can Trustwave WAF detect and mitigate "slow HTTP" attacks?

Information:

Yes, WAF 8.0 and above can detect, report, and prevent slow client Denial of Service (DoS) attacks, where an attacker deliberately sends multiple partial HTTP requests to the server. 

In such an attack, the client attempts to consume server resources by slowing the request or response, holding connections and memory resources open on the server for a long time, but without triggering session time-outs. This behavior can make the server unable to respond to legitimate requests from other clients.


To contact LevelBlue about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.