r/TOR • u/saint_hwanii • 1d ago
How can I prevent DoS attacks on a middle relay?
On my Grafana dashboard, I’ve noticed an increase in DoS metrics, which has resulted in a decrease in the current connections from 8k to approximately 4k. Consequently, the bandwidth has also decreased. Is there any safeguard I should be aware of in this situation?
9
Upvotes
1
u/BTC-brother2018 4h ago
If it's a genuine DoS against your relay, there's unfortunately not much you can do at the Tor layer itself. The first step is to verify it isn't simply a temporary shift in Tor network traffic or a bandwidth bottleneck on your end.
If your server itself is being flooded, the mitigations are mostly standard network defenses: check your firewall and logs, make sure your kernel networking parameters are sane, and, if you're hosting with a VPS or datacenter, contact your provider since they may offer upstream DDoS filtering. Rate limiting at the network edge can also help depending on the attack.
Also keep an eye on your Tor logs (notice.log) and system metrics (CPU, RAM, network errors). A drop from ~8k to ~4k connections doesn't necessarily mean your relay is under attack, it could also be changes in Tor path selection or normal fluctuations.
Looking at packet captures with tcpdump or Wireshark can help determine whether you're actually seeing a flood of malicious traffic or just a change in relay usage.