Bot attacks, ranging from simple scrapers to sophisticated DDoS (Distributed Denial of Service) attempts, pose a unique challenge for modular hosting. Because this service automatically scales CPU and RAM to meet traffic demands, malicious bots can artificially inflate your resource usage, leading to higher operational costs without any increase in actual business value.
Table of Contents
Context
Elastic scaling is designed to handle sudden spikes in genuine traffic (e.g., a mention in the news or a viral social post). However, bots don’t distinguish between “good” and “bad” traffic. If 1,000 bots hit your site simultaneously, the server will scale up to stay online, consuming “Elastic Resources” that you are billed for. Protecting your store from these attacks is both a security measure and a cost-optimization strategy.
Identifying the Problem: Log Analysis
The first step in cost control is identifying whether your traffic is human or automated. On mybox.com, you have direct access to the raw data needed for this audit.
- Location: Access your hosting via FTP or SSH and navigate to the
.logs/www/directory. - What to look for:
- High frequency from a single IP: Thousands of requests in a few minutes from one source.
- Suspicious User Agents: Identifiers like “python-requests,” “Go-http-client,” or unknown scrapers.
- Patterns: Repeated requests to expensive resources, such as search pages or login forms, which consume more CPU than static pages.
Steps to Protect Your Resources and Budget
Implementing these defenses prevents “empty” traffic from triggering the elastic scaling mechanism.
1. Blocking via .htaccess (LiteSpeed Optimization)
Our servers utilize LiteSpeed, which processes .htaccess rules more efficiently than traditional Apache. You can stop known bad actors at the door by blocking their User Agent strings.
Apache
# Block specific malicious bots
BrowserMatchNoCase "BadBot" bots
BrowserMatchNoCase "EvilScraper" bots
BrowserMatchNoCase "MJ12bot" bots
Order Allow,Deny
Allow from ALL
Deny from env=bots
2. Cloudflare Integration (The “Edge” Shield)
Cloudflare is the most effective way to keep costs down on elastic scaling. By using a CDN, the “Bad” traffic is filtered at Cloudflare’s servers before it ever reaches our infrastructure.
- Under Attack Mode: If you notice a massive spike, you can enable this to present a challenge (like a CAPTCHA) to all visitors.
- WAF (Web Application Firewall): Automatically blocks known botnets and malicious patterns.
- Cost Impact: Since the traffic is blocked at the edge, your hosting plan doesn’t need to scale up, keeping your bill stable.
3. Rate Limiting
You can configure rules to limit how many times an IP can request a page per minute. This prevents scrapers from crawling your entire catalog in seconds and spiking your CPU usage.
Practical Implications
- Unplanned Scaling: Without bot protection, a single “scraping” bot could double your resource consumption for the hour it is active.
- Resource Efficiency: By blocking bots, you leave more “room” in your base resource allocation for real customers, delaying the need for elastic scaling and saving money.
- Expert Assistance: If you see a spike in your mybox panel billing but can’t find the source in your logs, our 24/7 Helpdesk can help identify the attack pattern and implement blocks for you.
Summary
In a modular hosting environment, Traffic = Cost. Malicious bots are essentially “stealing” your server resources. By regularly auditing your logs and utilizing tools like .htaccess blocks and Cloudflare, you ensure that you only pay for the traffic that actually grows your business.