Defensive Engineering: Implementing an HTTP Tarpit to Counter Bot Attacks
An HTTP tarpit (also known as a “tarpit response” or “slowloris defense”) intentionally delays server responses to exhaust an attacker’s connection pool, memory, and threads without consuming your own outgoing network bandwidth. Instead of sending a large file like a video, the server sends extremely small chunks of data at long intervals to keep the bot’s socket open indefinitely.
Infrastructure Risk & Prerequisites
Do not apply tarpitting globally across your entire site. Apply it strictly to flagged bot IP addresses or isolated malicious routes (e.g., /api/register). If applied indiscriminately, genuine users with slow connections will experience server timeouts, and your web server may run out of worker processes if worker limits are configured too low.
Implementation Strategy
1.Identify and Isolate Bot Traffic:Step 1.
Configure your Web Application Firewall (WAF) or Reverse Proxy (e.g., Nginx, Cloudflare) to flag requests matching bot behavior—such as missing standard headers, high-frequency POST requests, or known bad user agents.
Verification: Check your access logs to ensure legitimate user IPs are not triggering the bot rule.
2.Configure Slow Response Rate Limits in Nginx:Step 2.
Use Nginx’s limit_rate directive on the target membership endpoint to throttle response transmission to as low as 1 byte per second.
Nginx
location = /api/register {
# Restrict transmission speed for flagged requests
limit_rate 1;
# Hold response headers open
add_header Content-Type "text/plain";
return 200 "Processing registration request...";
}
Verification: Run curl -i -X POST [https://yourdomain.com/api/register](https://yourdomain.com/api/register) from a command line. The response should pause indefinitely after receiving the initial bytes without closing the connection.
3.Implement Application-Level Sleep Loops (Node.js / Express):Step 3.
If implementing directly in your backend application, stream space characters or white noise characters back to the client inside an interval loop before closing the connection.
JavaScript
app.post('/api/register', (req, res) => {
if (isBotRequest(req)) {
res.setHeader('Content-Type', 'text/plain');
// Send 1 character every 5 seconds to hold the socket open
const tarpitInterval = setInterval(() => {
res.write(' ');
}, 5000);
// Terminate connection after 5 minutes to prevent memory leaks
req.on('close', () => clearInterval(tarpitInterval));
setTimeout(() => {
clearInterval(tarpitInterval);
res.end();
}, 300000);
return;
}
// Process legitimate user registration...
});
Verification: Monitor server process CPU and memory usage using top or process monitoring tools during a test run to confirm resource consumption stays near zero while maintaining open connections.
When to Use Tarpitting vs. Direct Blocking
| Feature | HTTP Tarpit | Direct HTTP 403 / 429 Block |
| Bot Impact | Consumes bot sockets, memory, and threads | Immediate failure; bot instantly retries or switches IPs |
| Server Resource Usage | Low (if asynchronous/event-driven) | Zero (dropped at edge) |
| Primary Use Case | Distracting persistent scrapers & targeted credential bots | Handling large distributed DDoS attacks |
