关于Amazon Linux安装mod_evasive及EC2实例DDoS防护的技术问询
Great questions—let’s break this down step by step for you, focusing on practical, up-to-date guidance for Amazon Linux and AWS EC2.
1. Will Amazon add mod_evasive to its latest AMIs?
At the time of writing, Amazon does not have an official plan to include mod_evasive in its default Amazon Linux AMIs. The official AMIs prioritize stable, widely used core components that AWS supports directly. mod_evasive is a third-party Apache module, so you’ll need to install it manually (which we cover below).
You can check for pre-packaged versions via amazon-linux-extras, but as of now, it’s not available there—so manual compilation is the reliable path.
2. Installing mod_evasive on Amazon Linux 2023 (Latest Version)
Here’s a tested, step-by-step guide tailored to the latest Amazon Linux distro:
Install dependencies: First, grab the tools needed to compile the module:
sudo dnf update -y sudo dnf install httpd-devel gcc make -yDownload and compile mod_evasive:
- Get the latest source code from its official open-source repository (you can find it via standard code hosting platforms).
- Extract the archive and navigate to the source directory:
tar xzf mod_evasive-*.tar.gz cd mod_evasive-* - Compile and install the module using Apache’s extension tool
apxs:
Thesudo apxs -i -a -c mod_evasive24.c-iflag installs the module,-aadds it to Apache’s config automatically, and-ccompiles the source code.
Configure mod_evasive:
Create a dedicated config file to fine-tune behavior:sudo nano /etc/httpd/conf.d/mod_evasive.confPaste in these adjustable base settings (tweak values to match your normal traffic patterns):
DOSHashTableSize 3097 DOSPageCount 20 DOSSiteCount 100 DOSPageInterval 1 DOSSiteInterval 1 DOSBlockingPeriod 10 DOSEmailNotify your-email@example.com DOSLogDir "/var/log/mod_evasive"Set up the required log directory with proper permissions:
sudo mkdir -p /var/log/mod_evasive sudo chown apache:apache /var/log/mod_evasiveVerify installation:
Restart Apache and confirm the module is loaded:sudo systemctl restart httpd sudo httpd -M | grep evasiveYou’ll see
evasive24_module (shared)in the output if the installation worked.
3. DDoS Protection for EC2 & Securing Apache/WordPress Instances
AWS provides native DDoS tools, and you can layer open-source solutions to harden your Apache/WordPress stack:
AWS Native DDoS Protection
- AWS Shield Standard: Enabled by default for all EC2 instances. It defends against common volumetric and protocol-based attacks (like SYN floods or UDP floods).
- AWS Shield Advanced: For production workloads, this paid service adds real-time attack monitoring, access to AWS’s DDoS Response Team, and protection against larger, targeted attacks. It integrates seamlessly with CloudFront and Route 53.
Open-Source Firewall & Apache Component Hardening
Combine these layers to secure your instance:
a. Firewall Configuration (firewalld)
Use Amazon Linux’s default firewalld to limit excessive traffic:
- Restrict incoming connections to Apache ports (80/443) per IP:
Adjust thesudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="0.0.0.0/0" port port="80" protocol="tcp" limit value="100/min" accept' --permanent sudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="0.0.0.0/0" port port="443" protocol="tcp" limit value="100/min" accept' --permanent sudo firewall-cmd --reload100/minvalue based on your typical traffic volume.
b. Additional Apache Security Modules
- mod_security: Install this Web Application Firewall (WAF) to block malicious requests (e.g., SQL injection, XSS):
Enable the OWASP Core Rule Set (a free, maintained set of security rules) for robust protection.sudo dnf install mod_security -y - mod_ratelimit: Limit bandwidth per client to prevent resource exhaustion:
Configure it in Apache’s config to cap bandwidth for individual IPs.sudo dnf install mod_ratelimit -y
c. WordPress-Specific Hardening
- Disable XML-RPC if you don’t use it (it’s a common attack vector): Add this line to your
wp-config.php:define('XMLRPC_REQUEST', false); - Install a WordPress security plugin (like Wordfence) to block brute-force login attempts and scan for malware.
- Enable HTTPS via AWS Certificate Manager (ACM) and redirect all HTTP traffic to HTTPS in Apache.
- Use caching plugins (e.g., W3 Total Cache) to reduce server load and improve response times during traffic spikes.
Architecture Best Practices
- Use CloudFront: As a CDN, it caches static content, hides your EC2 instance’s IP, and absorbs traffic spikes before they reach your origin.
- Auto Scaling: Set up an Auto Scaling Group to add EC2 instances automatically during high traffic, ensuring you can handle increased load from DDoS attacks.
- Route 53 DNS: Use Route 53’s health checks and failover to redirect traffic to healthy instances if one is compromised.
内容的提问来源于stack exchange,提问作者Erkin Kholmatov

