dos-lab/README.md
2026-04-06 10:40:27 -03:00

83 lines
1.7 KiB
Markdown

# DoS Lab
A controlled lab environment to demonstrate and analyze Denial of Service (DoS) attacks against a simple API, focusing on performance limits, resource exhaustion, and mitigation strategies.
## Overview
This project simulates DoS scenarios against a containerized API to understand:
- How services fail under load
- Resource bottlenecks (CPU, memory, network)
- Basic mitigation techniques
**Disclaimer:** This lab is for educational purposes only. Run attacks **only on systems you own or are authorized to test**.
## Architecture
Attacker Script (GoldenEye)
↓
Target API (Node.js)
↓
Nginx Rate Limiting (optional)
## Tech Stack
- Node.js (API)
- Docker / Docker Compose
- Nginx (optional reverse proxy)
- GoldenEye (attack tool)
## Getting started
### 1. Clone the Repo
```bash
git clone https://github.com/gabeefranco/dos-lab
cd dos-lab
```
### 2. Start the environment
With Nginx Rate Limiting:
```bash
docker-compose -f docker-compose.limited.yml up
```
Without Rate Limiting:
```bash
docker-compose -f docker-compose.unlimited.yml up
```
### 3. Running the attack
The service runs on port 80 with Nginx and on port 3000 without it.
```bash
attacker/run_attack.sh PORT
```
## Experiments
I have tried different scenarios:
1. Baseline (no limits)
2. Limiting resources (with docker-compose)
3. Increasing number of requests in the attack script
4. Adding rate limiting with Nginx
## Mitigation ideas
- Rate Limiting (Nginx)
- Caching
- Horizontal Scaling
- Request Queueing
## What I learned
- Basic Networking
- How DoS attacks work under the hood
- How to prevent DoS attacks in web applications
- How to limit resources in docker compose
- How to configure rate limiting in Nginx