Analysis of HTTP DDoS Flood Attacks on Apache2 and Nginx Web Servers with Linux Ubuntu
Haotian Tang, Samad S. Kolahi, Liam Thompson · 2024
With the development of the Internet, HTTP Flood attacks, a method of cyber-attack that floods web servers with ostensibly authentic network Requests and causes them to lose their ability to provide normal services, are increasingly favoured by attackers. This paper investigated and evaluated the ability of the most recent versions of Apache and Nginx web servers to handle legitimate Requests during the HTTP DDoS Flood attack on Linux Ubuntu (22.04) in a controlled, real testbed environment. Two metrics, Transactions Per Second (TPS) and HTTP Requests Error Rate were collected and analysed. In the experiment, the Apache web server was attacked by malicious HTTP Request traffic of 10,000 Threads, each generating 10,000 Requests, Apache remained overloaded from the 48th second to the end and could not respond to the legitimate user. In contrast, Nginx was not always overloaded. Our experimental results show that Nginx can better handle legitimate Requests during HTTP DDoS Flood attacks due to its better Concurrency design and Event-Driven, Asynchronous Non-Blocking architecture.