Loadtesting websites & DoS attacks

I'm keen to run some tests against my website to tweak caching & measure metrics under duress.

Pretty sure I can manage the technical side of that. Less sure about whether LES style providers are OK with that & how sensitive the DDoS protections are. Anyone have any experience / insights to share with on that?

.
  1. Good plan?1 vote
    1. Yes
        0.00%
    2. No
        0.00%
    3. Nuke it from orbit
      100.00%

Comments

  • ionswitch_stanionswitch_stan OGRetired
    edited January 2020

    DDOS is generally very different from load testing. You aren't going to generate any meaningful load at couple hundred RPS that will trigger any hosts DDOS protections.

    There are various tools that are used in industry -- jmeter, vyatta, etc. If you want to really try to blow up your website, or do >1000 rps, serverless artillery is fun.

    If you try to benchmark your website as you do a DNS reflection attack, a host would take issue.

    Thanked by (1)havoc

    Ionswitch.com | High Performance VPS in Seattle and Dallas since 2018

  • @ionswitch_stan said: You aren't going to generate any meaningful load at couple hundred RPS that will trigger any hosts DDOS protections.

    That's comforting.

    I tried the free tier of loader.io before, but that doesn't have sufficient firepower & the paid one starts at 100 bucks. So current plan is to using azure server(s) with siege. Raw throughput between the two is good for just over a gigabit but I'm guessing perf3 throughput doesn't translate to http serving throughput.

    @ionswitch_stan said: serverless

    Now there is an idea.

  • edited January 2020

    @ionswitch_stan said: serverless artillery is fun.

    What is serverless artillery?

  • @Janevski said:
    What is serverless artillery?

    I think this is what he refers to: https://github.com/Nordstrom/serverless-artillery

    Thanked by (2)Janevski bikegremlin

    "Humanity is f*cked up" - Jay

  • spliticesplitice Hosting ProviderOG

    The level of load usually used to measure caching metrics is not a DDoS by most peoples metrics. Even if mitigation does activate on your site/service it's not likely to cost your upstream anything and therefore not be cared about.

    Thanked by (1)havoc

    X4B - DDoS Protection: Affordable Anycast DDoS protection including Layer 7 mitigation with PoPs in the Europe, Asia, North and South America.
    Latest Offer: Brazil Launch 2020 Offer

  • ClouviderClouvider Hosting ProviderOG

    Speak with your provider - nothing better than agreement in advance.

    Thanked by (1)imok
Sign In or Register to comment.