You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Amazon Linux安装mod_evasive及EC2实例DDoS防护的技术问询

Answers to Your Amazon Linux & EC2 Security Questions

Great questions—let’s break this down step by step for you, focusing on practical, up-to-date guidance for Amazon Linux and AWS EC2.

1. Will Amazon add mod_evasive to its latest AMIs?

At the time of writing, Amazon does not have an official plan to include mod_evasive in its default Amazon Linux AMIs. The official AMIs prioritize stable, widely used core components that AWS supports directly. mod_evasive is a third-party Apache module, so you’ll need to install it manually (which we cover below).

You can check for pre-packaged versions via amazon-linux-extras, but as of now, it’s not available there—so manual compilation is the reliable path.

2. Installing mod_evasive on Amazon Linux 2023 (Latest Version)

Here’s a tested, step-by-step guide tailored to the latest Amazon Linux distro:

  • Install dependencies: First, grab the tools needed to compile the module:

    sudo dnf update -y
    sudo dnf install httpd-devel gcc make -y
    
  • Download and compile mod_evasive:

    1. Get the latest source code from its official open-source repository (you can find it via standard code hosting platforms).
    2. Extract the archive and navigate to the source directory:
      tar xzf mod_evasive-*.tar.gz
      cd mod_evasive-*
      
    3. Compile and install the module using Apache’s extension tool apxs:
      sudo apxs -i -a -c mod_evasive24.c
      
      The -i flag installs the module, -a adds it to Apache’s config automatically, and -c compiles the source code.
  • Configure mod_evasive:
    Create a dedicated config file to fine-tune behavior:

    sudo nano /etc/httpd/conf.d/mod_evasive.conf
    

    Paste in these adjustable base settings (tweak values to match your normal traffic patterns):

    DOSHashTableSize    3097
    DOSPageCount        20
    DOSSiteCount        100
    DOSPageInterval     1
    DOSSiteInterval     1
    DOSBlockingPeriod   10
    DOSEmailNotify      your-email@example.com
    DOSLogDir           "/var/log/mod_evasive"
    

    Set up the required log directory with proper permissions:

    sudo mkdir -p /var/log/mod_evasive
    sudo chown apache:apache /var/log/mod_evasive
    
  • Verify installation:
    Restart Apache and confirm the module is loaded:

    sudo systemctl restart httpd
    sudo httpd -M | grep evasive
    

    You’ll see evasive24_module (shared) in the output if the installation worked.

3. DDoS Protection for EC2 & Securing Apache/WordPress Instances

AWS provides native DDoS tools, and you can layer open-source solutions to harden your Apache/WordPress stack:

AWS Native DDoS Protection

  • AWS Shield Standard: Enabled by default for all EC2 instances. It defends against common volumetric and protocol-based attacks (like SYN floods or UDP floods).
  • AWS Shield Advanced: For production workloads, this paid service adds real-time attack monitoring, access to AWS’s DDoS Response Team, and protection against larger, targeted attacks. It integrates seamlessly with CloudFront and Route 53.

Open-Source Firewall & Apache Component Hardening

Combine these layers to secure your instance:

a. Firewall Configuration (firewalld)

Use Amazon Linux’s default firewalld to limit excessive traffic:

  • Restrict incoming connections to Apache ports (80/443) per IP:
    sudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="0.0.0.0/0" port port="80" protocol="tcp" limit value="100/min" accept' --permanent
    sudo firewall-cmd --add-rich-rule='rule family="ipv4" source address="0.0.0.0/0" port port="443" protocol="tcp" limit value="100/min" accept' --permanent
    sudo firewall-cmd --reload
    
    Adjust the 100/min value based on your typical traffic volume.

b. Additional Apache Security Modules

  • mod_security: Install this Web Application Firewall (WAF) to block malicious requests (e.g., SQL injection, XSS):
    sudo dnf install mod_security -y
    
    Enable the OWASP Core Rule Set (a free, maintained set of security rules) for robust protection.
  • mod_ratelimit: Limit bandwidth per client to prevent resource exhaustion:
    sudo dnf install mod_ratelimit -y
    
    Configure it in Apache’s config to cap bandwidth for individual IPs.

c. WordPress-Specific Hardening

  • Disable XML-RPC if you don’t use it (it’s a common attack vector): Add this line to your wp-config.php:
    define('XMLRPC_REQUEST', false);
    
  • Install a WordPress security plugin (like Wordfence) to block brute-force login attempts and scan for malware.
  • Enable HTTPS via AWS Certificate Manager (ACM) and redirect all HTTP traffic to HTTPS in Apache.
  • Use caching plugins (e.g., W3 Total Cache) to reduce server load and improve response times during traffic spikes.

Architecture Best Practices

  • Use CloudFront: As a CDN, it caches static content, hides your EC2 instance’s IP, and absorbs traffic spikes before they reach your origin.
  • Auto Scaling: Set up an Auto Scaling Group to add EC2 instances automatically during high traffic, ensuring you can handle increased load from DDoS attacks.
  • Route 53 DNS: Use Route 53’s health checks and failover to redirect traffic to healthy instances if one is compromised.

内容的提问来源于stack exchange,提问作者Erkin Kholmatov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:37:34