Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9186817
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T19:37:24+00:00 2026-06-17T19:37:24+00:00

I have a web service which is secured with an SSL EV certificate. Lets

  • 0

I have a web service which is secured with an SSL EV certificate. Lets say it´s located at:
https://webservice.justawebservice.com/webservice/. Users are able to send messages to this web-service.

When a malicious person obtains possession of this URL, said person can show the WSDL and web the service location. But most importantly, he will be able to send in messages. There is some kind of authentication on the web-service, but only happens when a message is sent in (the message contains an username and password). A malicious person will be able to flood said webservice with loads of messages, which may cause it to go offline.

I want to secure this area, so when said person goes to the link he is asked for some kind of authentication.

What is the best way to do this? (If it’s possible)

Any help is greatly appreciated,

Thanks!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T19:37:25+00:00Added an answer on June 17, 2026 at 7:37 pm

    If your objective is to prevent DOS type of attack ‘flooding with requests’ then authentication is not a proper way of doing it as even properly authenticated client could cause flood by nature of not understanding how to use API or by bugs in his code etc.

    Proper way IMHO would be to develop some sort of ‘circuit breaker’ pattern in your code (as WS interceptor perhaps) which would look at number of requests coming (either from particular user or from ip address or in total or all of the above) and shortcut call execution by returning the error to the caller, therefore not consuming much of the resources on your system.

    This would be a good first step but not a complete guarantee against DOS attack (as your service would still consume resources to accept request and interpret it). Next step would be to try to block such clients on lowest level possible – e.g. on firewall just dropping TCP packets – there are few firewalls packages that simplify this task – e.g. AFP with ddos deflate and so on.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a web service to which users upload python scripts that are run
I have a web-service which I secured using certificates. Now, I want to identify
I am creating a web service for end users which will have a front-end
I have web service which i want to use to upload image to the
I have web service which return json string like : d={main0ID:abc.es/main,main1ID:ah/main} I wanna append
I have web-service which give list of property at a particular area My problem
I am a little confused about Accept-Encoding . I have Web Service which would
I have a WCF web service which is responsible for managing work sent from
I have a RESTful web service which runs on Glassfish Application Server. When I
I have a restful web service which can deal with DTOs in json format

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.