Skip to content
Cyber Attacks

Slowloris Attacks: How Low-Bandwidth Denial of Service Works

A single computer can hold thousands of connections open simultaneously, exhausting server resources without sending large amounts of data or crashing the system.

Slowloris Attacks: How Low-Bandwidth Denial of Service Works
Illustration: Malware Brief
Quick answer

Slowloris attacks keep HTTP connections open by sending partial requests at irregular intervals. This prevents the server from closing the idle connection, filling its connection pool. The result is a denial of service where legitimate users cannot connect, achieved with minimal bandwidth and no special tools.

What is a Slowloris attack?

A Slowloris attack is a denial-of-service method that targets web servers by opening multiple connections and keeping them open for as long as possible. Instead of flooding the server with large data packets, the attacker sends small, partial HTTP requests. The server waits for the rest of the request to arrive, consuming a slot in its connection pool. This prevents other users from establishing new connections until the slots free up.

Infographic: Slowloris Attacks: How Low-Bandwidth Denial of Service Works. Attacks exploit the time servers wait for incomplete HTTP requests before timing out. Standard firewalls often fail to block these attacks because the traffic appears as valid, low-volume HTTP. Mitigation requires limiting co
Infographic: Slowloris Attacks: How Low-Bandwidth Denial of Service Works. Free to share with a link to Malware Brief.

How does the attacker keep connections open?

The attacker sends the initial part of an HTTP request, such as the header, but deliberately withholds the final newline or body data. The server, following standard protocol, waits for the complete request before processing or closing the link. The attacker then sends a single byte of data just before the server’s timeout period expires. This resets the timer, keeping the connection alive indefinitely. This cycle repeats for thousands of concurrent connections from a single source.

Why is this attack so effective against web servers?

Web servers allocate a fixed number of resources to handle simultaneous connections. When every available slot is occupied by these slow, incomplete requests, the server cannot accept new connections from legitimate users. The attack requires very little bandwidth, often less than one kilobyte per second per connection. This makes it difficult to detect through volume-based monitoring, which typically looks for sudden spikes in data transfer.

Can a single computer launch a Slowloris attack?

Yes, a single laptop or desktop can maintain thousands of concurrent connections to a vulnerable server. The limiting factor is usually the number of available TCP ports on the attacker’s machine, not processing power or bandwidth. Because the attack sends data so slowly, the network interface card does not become saturated. This allows an individual to take down a moderately sized website without needing a botnet or distributed infrastructure.

Do standard firewalls stop Slowloris attacks?

Most traditional firewalls and intrusion prevention systems do not block Slowloris attacks by default. These tools often inspect traffic for known malicious signatures or unusually high volumes of data. Since Slowloris traffic looks like legitimate, albeit slow, HTTP communication, it passes through standard filters. The packets are valid TCP segments with correct checksums, so they do not trigger basic anomaly detection rules.

See also: SIM Swapping Explained: How Attackers Steal Your Identity

How do web servers differ in their vulnerability?

Servers that wait for the complete HTTP request before processing are the most vulnerable. Some servers process headers as they arrive, which reduces the window for exploitation. However, many popular server configurations still reserve resources for incomplete requests to handle large file uploads or complex API calls. This design choice creates a trade-off between functionality and resilience against slow-rate attacks.

What is the difference between Slowloris and HTTP flood?

A Slowloris attack focuses on connection duration, using minimal data to occupy server slots. An HTTP flood attack focuses on connection volume, sending many complete requests per second to exhaust processing power. Slowloris is a layer 7 attack that exploits protocol timeouts, while HTTP floods often rely on botnets to generate high throughput. Both result in denial of service, but they require different mitigation strategies.

FeatureSlowloris AttackHTTP Flood Attack
Primary GoalExhaust connection slotsExhaust CPU or memory
Data VolumeVery lowVery high
Source DiversitySingle source possibleRequires botnet
Detection MethodConnection duration analysisRequest rate analysis

How can you detect a Slowloris attack in progress?

Look for a high number of established connections from a small number of IP addresses. These connections will show little to no data transfer over extended periods. Web server logs may reveal many requests that never complete or return status codes. Monitoring tools should track the duration of open connections, not just the volume of traffic. An unusual spike in connection duration is a stronger indicator than bandwidth usage.

What is the most effective mitigation strategy?

The most reliable defence is to limit the number of concurrent connections per IP address at the web server or reverse proxy level. Setting a lower timeout for incomplete requests also helps, though it may impact legitimate users on slow networks. Using a web application firewall that can inspect HTTP behaviour can identify and drop partial requests. These measures add overhead but protect the server from resource exhaustion.

Does using HTTPS change the attack dynamics?

HTTPS encryption does not prevent Slowloris attacks, as the exploit occurs at the TCP connection level before full HTTP processing. The attacker still opens TCP connections and sends partial TLS handshake or HTTP data. However, some HTTPS implementations may have different timeout behaviours that could slightly alter the attack window. Encryption adds complexity for the attacker but does not remove the fundamental vulnerability of connection pooling.

How does this relate to other denial-of-service methods?

Slowloris is a specific type of application-layer attack, distinct from network-layer floods that saturate bandwidth. It shares similarities with other slow-rate attacks that exploit protocol inefficiencies. Understanding this helps in designing incident response plans that account for low-volume, high-impact threats. Unlike phishing kits that target user credentials, this targets server infrastructure directly. It is a reminder that infrastructure security requires looking beyond simple traffic volume.

Can load balancers help prevent these attacks?

Load balancers can mitigate the impact by distributing connections across multiple backend servers. If one server fills up, the balancer can route new connections to others. However, if the attack targets the load balancer itself, or if all backend servers are vulnerable, the protection is limited. Some load balancers offer features to drop idle connections or limit per-IP rates, which adds a layer of defence. This complements server-level configurations for a more resilient architecture.

What is the long-term outlook for this threat?

Slowloris remains a viable threat because it exploits fundamental aspects of how web servers manage resources. As long as servers must wait for complete requests, this vector exists. Defences evolve to detect behaviour rather than signatures, making attacks harder to execute successfully. This mirrors the evolution seen in defending against MFA fatigue attacks, where persistence is the weapon. Staying updated with server configuration best practices is the only sustainable defence.

Key takeaways

  • Attacks exploit the time servers wait for incomplete HTTP requests before timing out.
  • Standard firewalls often fail to block these attacks because the traffic appears as valid, low-volume HTTP.
  • Mitigation requires limiting concurrent connections per IP and configuring connection timeouts correctly.
Bottom line

Slowloris attacks exploit server connection limits using minimal bandwidth, making them hard to detect with standard tools. Configure connection limits and timeouts on your web server to protect against resource exhaustion.

Frequently asked questions

Is Slowloris still a relevant threat in modern infrastructure?

Yes, because it exploits basic HTTP protocol behaviours that are still present in most web server configurations.

Can cloud providers automatically block Slowloris attacks?

Many cloud providers offer managed web application firewalls that include protection against slow-rate attacks, but configuration is often required.

Does using a CDN prevent Slowloris attacks?

A CDN can absorb the attack by terminating connections at the edge, preventing them from reaching the origin server.

How do I test if my server is vulnerable?

You can use authorised testing tools to simulate slow connections and monitor server response times and connection counts.

How this guide was produced: written by the Malware Brief editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.

Further reading

  1. UK National Cyber Security Centre
  2. OWASP Foundation
  3. NIST Cybersecurity Framework

Related stories

How Slowloris Attacks Work: Step-by-Step Mechanics

A single connection can exhaust server resources by keeping HTTP requests open indefinitely, requiring no bandwidth or complex tools.

Cybersecurity news without the noiseDaily Briefing