83 lines
1.7 KiB
Markdown
83 lines
1.7 KiB
Markdown
# DoS Lab
|
|
|
|
A controlled lab environment to demonstrate and analyze Denial of Service (DoS) attacks against a simple API, focusing on performance limits, resource exhaustion, and mitigation strategies.
|
|
|
|
## Overview
|
|
|
|
This project simulates DoS scenarios against a containerized API to understand:
|
|
|
|
- How services fail under load
|
|
- Resource bottlenecks (CPU, memory, network)
|
|
- Basic mitigation techniques
|
|
|
|
**Disclaimer:** This lab is for educational purposes only. Run attacks **only on systems you own or are authorized to test**.
|
|
|
|
## Architecture
|
|
|
|
Attacker Script (GoldenEye)
|
|
↓
|
|
Target API (Node.js)
|
|
↓
|
|
Nginx Rate Limiting (optional)
|
|
|
|
## Tech Stack
|
|
|
|
- Node.js (API)
|
|
- Docker / Docker Compose
|
|
- Nginx (optional reverse proxy)
|
|
- GoldenEye (attack tool)
|
|
|
|
## Getting started
|
|
|
|
### 1. Clone the Repo
|
|
|
|
```bash
|
|
git clone https://github.com/gabeefranco/dos-lab
|
|
cd dos-lab
|
|
```
|
|
|
|
### 2. Start the environment
|
|
|
|
With Nginx Rate Limiting:
|
|
|
|
```bash
|
|
docker-compose -f docker-compose.limited.yml up
|
|
```
|
|
|
|
Without Rate Limiting:
|
|
|
|
```bash
|
|
docker-compose -f docker-compose.unlimited.yml up
|
|
```
|
|
|
|
### 3. Running the attack
|
|
|
|
The service runs on port 80 with Nginx and on port 3000 without it.
|
|
|
|
```bash
|
|
attacker/run_attack.sh PORT
|
|
```
|
|
|
|
## Experiments
|
|
|
|
I have tried different scenarios:
|
|
|
|
1. Baseline (no limits)
|
|
2. Limiting resources (with docker-compose)
|
|
3. Increasing number of requests in the attack script
|
|
4. Adding rate limiting with Nginx
|
|
|
|
## Mitigation ideas
|
|
|
|
- Rate Limiting (Nginx)
|
|
- Caching
|
|
- Horizontal Scaling
|
|
- Request Queueing
|
|
|
|
## What I learned
|
|
|
|
- Basic Networking
|
|
- How DoS attacks work under the hood
|
|
- How to prevent DoS attacks in web applications
|
|
- How to limit resources in docker compose
|
|
- How to configure rate limiting in Nginx
|