Defensive Engineering: Implementing an HTTP Tarpit to Counter Bot Attacks

Defensive Engineering: Implementing an HTTP Tarpit to Counter Bot Attacks

An HTTP tarpit (also known as a “tarpit response” or “slowloris defense”) intentionally delays server responses to exhaust an attacker’s connection pool, memory, and threads without consuming your own outgoing network bandwidth. Instead of sending a large file like a video, the server sends extremely small chunks of data at long intervals to keep the bot’s socket open indefinitely.

Infrastructure Risk & Prerequisites

Do not apply tarpitting globally across your entire site. Apply it strictly to flagged bot IP addresses or isolated malicious routes (e.g., /api/register). If applied indiscriminately, genuine users with slow connections will experience server timeouts, and your web server may run out of worker processes if worker limits are configured too low.

Implementation Strategy

1.Identify and Isolate Bot Traffic:Step 1.

Configure your Web Application Firewall (WAF) or Reverse Proxy (e.g., Nginx, Cloudflare) to flag requests matching bot behavior—such as missing standard headers, high-frequency POST requests, or known bad user agents.

Verification: Check your access logs to ensure legitimate user IPs are not triggering the bot rule.

2.Configure Slow Response Rate Limits in Nginx:Step 2.

Use Nginx’s limit_rate directive on the target membership endpoint to throttle response transmission to as low as 1 byte per second.

Nginx

location = /api/register {
    # Restrict transmission speed for flagged requests
    limit_rate 1; 
    
    # Hold response headers open
    add_header Content-Type "text/plain";
    return 200 "Processing registration request...";
}

Verification: Run curl -i -X POST [https://yourdomain.com/api/register](https://yourdomain.com/api/register) from a command line. The response should pause indefinitely after receiving the initial bytes without closing the connection.

3.Implement Application-Level Sleep Loops (Node.js / Express):Step 3.

If implementing directly in your backend application, stream space characters or white noise characters back to the client inside an interval loop before closing the connection.

JavaScript

app.post('/api/register', (req, res) => {
  if (isBotRequest(req)) {
    res.setHeader('Content-Type', 'text/plain');
    
    // Send 1 character every 5 seconds to hold the socket open
    const tarpitInterval = setInterval(() => {
      res.write(' ');
    }, 5000);

    // Terminate connection after 5 minutes to prevent memory leaks
    req.on('close', () => clearInterval(tarpitInterval));
    setTimeout(() => {
      clearInterval(tarpitInterval);
      res.end();
    }, 300000);
    return;
  }
  
  // Process legitimate user registration...
});

Verification: Monitor server process CPU and memory usage using top or process monitoring tools during a test run to confirm resource consumption stays near zero while maintaining open connections.

When to Use Tarpitting vs. Direct Blocking

FeatureHTTP TarpitDirect HTTP 403 / 429 Block
Bot ImpactConsumes bot sockets, memory, and threadsImmediate failure; bot instantly retries or switches IPs
Server Resource UsageLow (if asynchronous/event-driven)Zero (dropped at edge)
Primary Use CaseDistracting persistent scrapers & targeted credential botsHandling large distributed DDoS attacks

Leave a Reply

Your email address will not be published. Required fields are marked *