Server
Slowloris
Slowloris is a denial-of-service technique that opens many connections and sends request data very slowly, so the server keeps each slot busy and has none left for real visitors. It needs little bandwidth.
How it is measured
Look at connection states and ages. Many connections from a few IPs in the reading-headers state, each open for minutes and sending a byte every 10 seconds, are the signature. `ss -tn state established | wc -l` and the web server's status page show the count.
Requests per second may look normal or low while the worker or connection limit is full. The tell is the mismatch between connection count and completed requests.
Worked example
An Apache server allows 256 concurrent connections. At 14:20 a single address opens 240 and sends a partial header every 15 seconds. Real visitors get queued or refused, response time rises to 30 seconds, and the access log is almost silent because no request ever finishes.
Switching to Nginx in front, which buffers slow clients cheaply, with `client_header_timeout 10s` and a per-IP connection limit of 20, ended the attack's effect. A CDN in front would have absorbed it too.
How it differs
Slowloris exhausts connection slots using slow, valid-looking requests. A DDoS floods with volume from many sources. Slowloris excludes high bandwidth, and one machine can do it. A flood excludes subtlety, since the traffic is obviously large. Defending against one is about timeouts and limits, against the other it is about capacity and filtering.
Common errors
Looking for a traffic spike that does not exist. Raising the connection limit instead of shortening the header timeout. Setting very long keep-alive and read timeouts. Running a thread-per-connection server directly on the internet. Blocking IPs one at a time when a CDN would handle it.
In practice
Set short header and body read timeouts, limit connections per IP, and put an event-driven proxy or a CDN in front of thread-based servers. Check your server status page for old connections stuck in reading state.