# DoS Lab A controlled lab environment to demonstrate and analyze Denial of Service (DoS) attacks against a simple API, focusing on performance limits, resource exhaustion, and mitigation strategies. ## Overview This project simulates DoS scenarios against a containerized API to understand: - How services fail under load - Resource bottlenecks (CPU, memory, network) - Basic mitigation techniques **Disclaimer:** This lab is for educational purposes only. Run attacks **only on systems you own or are authorized to test**. ## Architecture Attacker Script (GoldenEye) ↓ Target API (Node.js) ↓ Nginx Rate Limiting (optional) ## Tech Stack - Node.js (API) - Docker / Docker Compose - Nginx (optional reverse proxy) - GoldenEye (attack tool) ## Getting started ### 1. Clone the Repo ```bash git clone https://github.com/gabeefranco/dos-lab cd dos-lab ``` ### 2. Start the environment With Nginx Rate Limiting: ```bash docker-compose -f docker-compose.limited.yml up ``` Without Rate Limiting: ```bash docker-compose -f docker-compose.unlimited.yml up ``` ### 3. Running the attack The service runs on port 80 with Nginx and on port 3000 without it. ```bash attacker/run_attack.sh PORT ``` ## Experiments I have tried different scenarios: 1. Baseline (no limits) 2. Limiting resources (with docker-compose) 3. Increasing number of requests in the attack script 4. Adding rate limiting with Nginx ## Mitigation ideas - Rate Limiting (Nginx) - Caching - Horizontal Scaling - Request Queueing ## What I learned - Basic Networking - How DoS attacks work under the hood - How to prevent DoS attacks in web applications - How to limit resources in docker compose - How to configure rate limiting in Nginx