Original title:
Zátěžové testování pomalých DDoS útoků pomocí platformy Apache Jmeter
Translated title:
Stress testing slow DDoS attacks using Apache Jmeter platform
Authors:
Čurilla, Jakub ; Člupek, Vlastimil (referee) ; Sikora, Marek (advisor) Document type: Master’s theses
Year:
2025
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
V súčasnosti sa pomalé DoS útoky stávajú čoraz relevantnejšou hrozbou, ktorá využíva špecifiká aplikačnej vrstvy na vyčerpanie serverových zdrojov. Tieto útoky sú účinné najmä vďaka tomu, že napodobňujú správanie legitímnych klientov s nízkou prenosovou rýchlosťou, čím sa vyhýbajú tradičným detekčným mechanizmom. Diplomová práca sa zaoberá návrhom a implementáciou univerzálneho nástroja pre generovanie pomalých DoS a DDoS útokov v rámci platformy Apache JMeter, ktorý umožňuje simulovať rôzne typy aplikačných útokov v realistických podmienkach. Cieľom práce bolo vytvoriť plne konfigurovateľný modul s podporou protokolov HTTP aj HTTPS, IPv4 aj IPv6, a možnosťou výberu medzi režimom DoS a DDoS. Modul umožňuje generovať tieto SDoS útoky Súčasťou riešenia je grafické rozhranie, konfigurácia parametrov, zber výstupov, vizualizácia priebehu útoku a meranie dostupnosti cieľového servera v reálnom čase. Implementovaný modul bol testovaný v lokálnej sieti na serveroch Apache a NGINX, pričom boli analyzované rozdiely v správaní pri jednotlivých typoch útokov. Merania potvrdili, že Apache server je výrazne náchylnejší na pomalé útoky - už pri niekoľkých stovkách spojení dochádzalo k úplnej nedostupnosti služby. NGINX preukázal vyššiu odolnosť a schopnosť zotaviť sa po prechodnom zahltení, pričom dokázal udržať stovky až tisíce spojení bez výpadku. Výsledky sú doplnené o vizualizácie a analýzu vyťaženia systémových prostriedkov počas útoku.
Currently, slow DoS attacks are becoming an increasingly relevant threat that uses the specifics of the application layer to exhaust server resources. These attacks are effective mainly because they mimic the behavior of legitimate clients with low transmission speed, thus avoiding traditional detection mechanisms. The thesis deals with the design and implementation of a universal tool for generating slow DoS and DDoS attacks within the Apache JMeter platform, which allows simulating various types of application attacks in realistic conditions. The aim of the work was to create a fully configurable module with support for HTTP and HTTPS protocols, IPv4 and IPv6, and the ability to choose between DoS and DDoS modes. The module allows generating these SDoS attacks. The solution includes a graphical interface, parameter configuration, output collection, visualization of the attack progress and measurement of the target server availability in real time. The implemented module was tested in a local network on Apache and NGINX servers, and differences in behavior during individual types of attacks were analyzed. Measurements confirmed that the Apache server is significantly more susceptible to slow attacks - even with a few hundred connections, the service was completely unavailable. NGINX demonstrated higher resilience and the ability to recover from transient congestion, while being able to maintain hundreds to thousands of connections without downtime. The results are supplemented with visualizations and analysis of system resource utilization during the attack.
Keywords:
Apache; Apache JMeter; Application Layer; Attack Detection; Attack Generator; Attack Visualization; NGINX; R.U.D.Y.; Server stress testing; Slow DDoS; Slow DoS; Slow POST; Slow Read; Slowloris; Web Server; Apache; Apache JMeter; Aplikačná vrstva; Detekcia útokov; Generátor útokov; NGINX; R.U.D.Y.; Slow DDoS; Slow DoS; Slow POST; Slow Read; Slowloris; Vizualizácia útoku; Webový server; Záťažové testovanie serverov
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/251449