Bot attacks, especially those resembling DDoS (Distributed Denial of Service) attacks, can put a significant strain on server resources. With Elastic Web Hosting, the server automatically adjusts its resources to the current load. However, excessive traffic generated by malicious bots can lead to an unplanned increase in resource consumption, which in turn can increase the cost of maintaining the service.
Table of Contents
Analysis of server logs as the key to identifying the problem
To effectively counteract unwanted traffic, it is worth regularly analyzing the logs of the web server. In mybox.com, these logs are available in a .logs/www directory in your hosting account. You can access them through an FTP or SSH connection. In the logs, you will find information about all requests made to your website, including IP addresses, timestamps and user IDs (User-Agent). Detailed information on access to logs can be found in the article: Web server and mail logs.
Steps to take to protect yourself from malicious bots
- Blocking bots with .htaccess file – The LiteSpeed server we use allows you to create rules in the
.htaccess. This allows you to block access to unwanted bots based on their User-Agent ID. An example rule that blocks specific bots might look like this:BrowserMatchNoCase "BadBot" bots BrowserMatchNoCase "EvilScraper" bots Order Allow,Deny Allow from ALL Deny from env=botsIn the example above, bots named “BadBot” and “EvilScraper” will be blocked. You can customize the list of unwanted bots to suit your needs. - Using services such as Cloudflare – is a CDN (Content Delivery Network) service that offers additional protection against DDoS attacks and malicious bots. Integration with Cloudflare can help you filter your traffic and block unwanted requests before they reach your server. This will reduce server load and potential costs associated with excessive resource consumption.
- Contact Customer Service – if the problem persists despite the actions taken, it is worth contacting Customer Service. Specialists available through the Helpdesk 24h can help with the analysis of logs and propose additional security measures.
Summary
Regular analysis of server logs and implementation of appropriate protection mechanisms, such as rules in the file .htaccess or integration with services such as Cloudflare, can significantly reduce the risk of bot attacks. This will not only secure your website, but also minimize the potential costs associated with excessive resource consumption with Elastic Web Hosting.