Description

Does Corero support Low and Slow attack detection?

Symptoms

Does Corero support Low and Slow attack detection?

Solution

  • Low and slow attacks are not volumetric DDoS attacks but rather a DoS attack that emulates slow TCP clients to starve servers' TCP connection resources.
  • Detecting this would require a detailed TCP flow analysis (tracking), which is not something Corero is designed for. The TDD product is specifically aimed at Volumetric DDoS. The description of "Low and Slow" provided in the Cloudflare article would not be considered Volumetric and therefore would not be covered by the TDD product.
  • Non-volumetric DoS attacks are typically enforced at the edge firewalls or even on the servers where the number of TCP sessions is considerably lower compared to the network backbone.

Modification History

2024-10-09 : Article Created