Description
Does Corero support Low and Slow attack detection?
Symptoms
Does Corero support Low and Slow attack detection?
Solution
Low and slow attacks are not volumetric DDoS attacks but rather a DoS attack that emulates slow TCP clients to starve servers' TCP connection resources.
Detecting this would require a detailed TCP flow analysis (tracking), which is not something Corero is designed for. The TDD product is specifically aimed at Volumetric DDoS. The description of "Low and Slow" provided in the Cloudflare article would not be considered Volumetric and therefore would not be covered by the TDD product.
Non-volumetric DoS attacks are typically enforced at the edge firewalls or even on the servers where the number of TCP sessions is considerably lower compared to the network backbone.
Modification History
2024-10-09 : Article Created
Corero Response to low and slow Attack