I am trying to stop abusers flooding my Apache web server with break-in attempts, sometimes at the rate of over 100/second. Part of my strategy is to install www/ap24_mod_evasive and set
DOSSiteCount 20
DOSSiteInterval 1
and in httpd.conf
MaxKeepAliveRequests 21
My pages all have fewer than that number of included files (images, stylesheets and scripts) so this would not slow access at normal human rates down.
However, it's not slowing the bots down either. As I understand it evasive should block further connections when 15 requests in a second is exceeded and Apache should kill the connection after 21 requests from the same source, but this obviously isn't working if a bot working from the same IP address can make 100 requests in a second.
Is there something I need to do in addition to installing and configuring the numbers?
DOSSiteCount 20
DOSSiteInterval 1
and in httpd.conf
MaxKeepAliveRequests 21
My pages all have fewer than that number of included files (images, stylesheets and scripts) so this would not slow access at normal human rates down.
However, it's not slowing the bots down either. As I understand it evasive should block further connections when 15 requests in a second is exceeded and Apache should kill the connection after 21 requests from the same source, but this obviously isn't working if a bot working from the same IP address can make 100 requests in a second.
Is there something I need to do in addition to installing and configuring the numbers?