[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] adaption of a DDoS prevention solution



Recent DDoS attacks caused me to update the DDoS solution [1] and to roll it out to Tor instances using [2].

The metrics below shows the effect for the (highly overloaded vCPU before), the throughput and the amount of protocol violations of a tiny Tor cloud instance:







Another example is Tor instance at a bare metal server, attacked between 12 and 13 UTC (no Tor metrics during that time) and again after 16 UTC. The new rule set was developed between 14 and 15, and fully applies after a reboot at 15:20:



The graph below shows that the ipset (which holds malicious ip addresses to be blocked) was not updated at the first attack.
But with the new rule set in place it was updated soon at the 2nd attack.
The yellow line in the 2nd graph shows the portion of the change.



And finally the DOS Tor metric for this instance indicates that the Tor process has much less DOS to handle than before:



I'm still fine tuning the solution.


[1] https://github.com/toralf/torutils#the-rule-set
[2] https://github.com/toralf/tor-relays

--
Toralf

_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx