Mitigating Slow HTTP Post DDoS Attacks With iRules
Published Nov 05, 2010
Version 1.0Was this article helpful?
Add a log statement before the TCP::close action. Something like this should work:
log local0. "Slow post detected from [IP::addr]. Connection closed."