top | item 9099771

(no title)

Benferhat | 11 years ago

I might even incorporate the request rate into a bot detection algo, maybe have it trigger temporary hellbans.

discuss

order

rdl|11 years ago

Request rate is definitely one thing you can limit, but it's tricky when attackers potentially control large numbers of IP addresses.

There's an annoying triangle here: wanting to preserve privacy (== unlinkability), machine-independence, and "working well for good traffic with limited resources, as well as blocking attackers with substantially more resources". Ideally it is "choose zero", I'd be happy if the state of the art were even at "choose one".

rdl|11 years ago

er, I meant choose two, and we're generally at zero or one.