简体   繁体   English

如何处理大型有效载荷攻击?

[英]How to handle large payload attacks?

I have soap based large payload (bytes) data on webservice call. 我在webservice调用上有基于soap的大有效负载(字节)数据。 How do i ensure that application will be proof from: 我如何确保该应用程序可以提供以下证明:

  • Malicious client generating fake requests with large payload keeping server busy handling fake requests? 恶意客户端生成具有大负载的虚假请求,使服务器忙于处理虚假请求吗?
  • How to reject extremely large payload before encountering OME to protect server crash? 在遇到OME之前如何拒绝极大的有效负载以保护服务器崩溃?

Unless you authenticate your clients either via SSL authentication or at least via login it is extremely difficult to distinguish valid and fake requests that could cause DoS. 除非您通过SSL身份验证或至少通过登录对客户端进行身份验证,否则很难区分可能导致DoS的有效和虚假请求。 In the latter case hire a professional consultant. 在后一种情况下,请聘请专业顾问。 My 2 cents on this... 我的2美分...

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM