dos-lab/README.md
2026-04-06 10:40:27 -03:00

1.7 KiB

DoS Lab

A controlled lab environment to demonstrate and analyze Denial of Service (DoS) attacks against a simple API, focusing on performance limits, resource exhaustion, and mitigation strategies.

Overview

This project simulates DoS scenarios against a containerized API to understand:

  • How services fail under load
  • Resource bottlenecks (CPU, memory, network)
  • Basic mitigation techniques

Disclaimer: This lab is for educational purposes only. Run attacks only on systems you own or are authorized to test.

Architecture

Attacker Script (GoldenEye) ↓ Target API (Node.js) ↓ Nginx Rate Limiting (optional)

Tech Stack

  • Node.js (API)
  • Docker / Docker Compose
  • Nginx (optional reverse proxy)
  • GoldenEye (attack tool)

Getting started

1. Clone the Repo

git clone https://github.com/gabeefranco/dos-lab
cd dos-lab

2. Start the environment

With Nginx Rate Limiting:

docker-compose -f docker-compose.limited.yml up

Without Rate Limiting:

docker-compose -f docker-compose.unlimited.yml up

3. Running the attack

The service runs on port 80 with Nginx and on port 3000 without it.

attacker/run_attack.sh PORT

Experiments

I have tried different scenarios:

  1. Baseline (no limits)
  2. Limiting resources (with docker-compose)
  3. Increasing number of requests in the attack script
  4. Adding rate limiting with Nginx

Mitigation ideas

  • Rate Limiting (Nginx)
  • Caching
  • Horizontal Scaling
  • Request Queueing

What I learned

  • Basic Networking
  • How DoS attacks work under the hood
  • How to prevent DoS attacks in web applications
  • How to limit resources in docker compose
  • How to configure rate limiting in Nginx