> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/reference/web-ddos-mitigation-reasons.md).

# Web DDoS Mitigation Reasons

As described below, Web DDoS evaluates requests based on a number of factors. As anomalies accumulate, the "Sumpoints" value rises. If Sumpoints becomes too large, requests are blocked.

Below is a list of anomalies/errors that will trigger DDoS mitigation.&#x20;

<table><thead><tr><th width="166">Type</th><th width="333">Error(s)/Algorithm(s)</th><th>Explanation</th></tr></thead><tbody><tr><td><strong>Invalid HTTP Request</strong><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></td><td><ul><li>STATS_NEVERSTARTEDHEADER</li><li>STATS_HTTPUNKNOWNMETHOD</li><li>STATS_HTTPNOVER</li><li>STATS_HTTPNOTV1</li><li>STATS_TRASHAFTERCRLFCRLF</li><li>STATS_ZEROBYTEINHEADER</li><li>STATS_HTTPMISSINGCONTENTLENGTH</li><li>STATS_ALREADYHASXDDOSPROXY</li><li>STATS_HTTPEMPTYREQUEST</li><li>STATS_HTTPONHTTPS<br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></li></ul></td><td><p>An 'Invalid HTTP Request' error message can occur for a variety of reasons, and the most common ones include issues related to header submission, HTTP verb usage, HTTP version compatibility, content-length header, and protocol mismatch. </p><ul><li>The client made a connection but did not submit a header within 32 seconds</li><li>The client provided a HTTP verb that is not known</li><li>The client performed a request without an HTTP version</li><li>The client performed a request without HTTP/1. version against an HTTP1.x endpoint</li><li>The client performed a request that contained data after the header ended</li><li>The client performed a request without header end marker or without line end</li><li>The client failed to provide a content-length header, although one is required</li><li>The client performed an HTTP request against an HTTPS port<br></li></ul></td></tr><tr><td><strong>Policy Violation</strong><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></td><td><ul><li>STATS_BIGHEADER</li><li>STATS_HTTPREFERERWOHTTP</li><li>STATS_HTTPLONGREQUEST</li><li>STATS_HTTPLONGUSERAGENT</li><li>STATS_HTTPLONGREFERER</li><li>STATS_HTTPLONGHOST</li><li>STATS_HTTPLONGCOOKIEHEADER</li><li>STATS_HTTPUNKNOWNHOST</li><li>STATS_HTTPBLACKLISTEDHOST</li><li>STATS_HTTPSMALLREFERER</li><li>STATS_HTTPLONGRANGE</li><li>STATS_HTTPBIGBODY</li><li>STATS_HTTPLISTENIP<br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></li></ul></td><td><p>When a client's request violates a policy, it means that the request made by the client falls outside of our internal guidelines. This could be due to a number of reasons:</p><ul><li>The client performed a request with an abnormally large header.</li><li>The client performed a request containing a referer without proper protocol specification.</li><li>The client requested a URL longer than the maximum configured request size (which can be configured by support).</li><li>The client performed a request containing a user-agent longer than the configured maximum user-agent size (which can be configured by support).</li><li>The client performed a request containing a referrer longer than the configured maximum referrer size (which can be configured by support).</li><li>The client performed a request containing a host header longer than the configured maximum host header size (which can be configured by support).</li><li>The client performed a request containing a cookie header longer than the configured maximum cookie header size (which can be configured by support).</li><li>The client performed a request containing a range header longer than the configured maximum range header size (which can be configured by support).</li><li>The client performed a post request exceeding the configured maximum post size.</li><li>The webddos proxy connection was accessed via its IP address.</li><li>The whitelist is enabled but the IP is not on the whitelist.</li><li>The blacklist is enabled and the IP is on the blacklist.</li><li>The client performed a request containing a very short referrer.</li></ul></td></tr><tr><td><strong>Uncommon HTTP Profile</strong><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></td><td><ul><li>STATS_SLOWHEADER</li><li>STATS_NOACCEPTENCODINGHEADER</li><li>STATS_NOUSERAGENTHEADER</li><li>STATS_NOACCEPTHEADER</li><li>STATS_SMALLHEADER</li><li>STATS_NOREFERERHEADER</li><li>STATS_HTTPREFERERWOURI</li><li>STATS_HTTPLOTSOFRANGES</li><li>STATS_HTTPHEAD</li><li>STATS_HTTPREST</li><li>STATS_HTTPOPTIONS</li><li>STATS_HTTPPROPFIND</li><li>STATS_HTTPDELETE</li><li>STATS_HTTPPUT</li><li>STATS_HTTPRANGEHEADER</li><li>STATS_HTTPREFERERONEDOT<br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></li></ul></td><td><p>An "Uncommon HTTP Profile" can indicate a variety of things:</p><ul><li>The client started submitting a header but did not finish within 10 seconds.</li><li>The client performed a request missing an Accept-Encoding header.</li><li>The client performed a request missing a User-Agent header.</li><li>The client performed a request missing an Accept header.</li><li>The client performed a request containing a very small header.</li><li>The client performed a request containing a referer without a URI.</li><li>The client performed a request containing lots of range headers.</li><li>The client performed a HEAD request.</li><li>The client performed a REST request.</li><li>The client performed an OPTIONS request.</li><li>The client performed a PROPFIND request.</li><li>The client performed a DELETE request.</li><li>The client performed a PUT request.</li><li>The client performed a request containing a Range header.</li><li>The client performed a request containing a referer which in turn contains an invalid URI.</li></ul></td></tr><tr><td><strong>Uncommon Visitor Profile</strong><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br></td><td><ul><li>STATS_HTTPSAMEURL</li><li>STATS_HTTPUSERAGENTSDIFFER</li><li>STATS_HTTP3xSPACEINUSERAGENT</li><li>STATS_HTTPUSERAGENTLOWERCASE</li><li>STATS_HTTPUSERAGENTUNCOMMON</li><li>STATS_HTTPONLYPOST</li><li>STATS_GEOIPBAD<br><br><br><br></li></ul></td><td><p>An “Uncommon Visitor Profile” typically indicates that the client is not a human. Uncommon visitors are often identified by:</p><ul><li>Spaces in the User Agent</li><li>fully lowercase User Agent strings</li><li>fully uppercase User Agents strings</li><li>Uncommon or rarely user User Agent strings</li><li>Making POST requests over HTTP<br></li></ul></td></tr><tr><td><strong>Very High Traffic Source</strong><br><br><br><br><br><br></td><td><ul><li>STATS_HITS_PER_SECOND_DROPPED</li><li>STATS_HITS_PER_SECOND</li><li>STATS_HITS_PER_SECOND_EXCEEDED</li></ul></td><td>The reasons for a "Very High Traffic Source" is due to the client exceeding 25 hits per second.<br><br><br></td></tr><tr><td><strong>Local Policy Violation</strong><br><br><br></td><td><ul><li>STATS_GEOIPNOTALLOWED</li><li>STATS_BLACKLISTEDIP</li></ul></td><td>IPs that are blacklisted either via countryrRestrictions or an explicit blacklist<br></td></tr><tr><td><strong>Mitigation Challenge Failed</strong><br><br><br><br><br><br><br><br><br></td><td><ul><li>STATS_MISSINGLDPCCOOKIE</li><li>STATS_RECAPTCHA_STARTED</li><li>STATS_RECAPTCHA_FAILED</li><li>STATS_RECAPTCHA_TOKEN_INVALID</li><li>STATS_HTTPINVALIDLDPCCOOKIE</li></ul></td><td>This is provided to the client when they are unsuccessful in one or more mitigation strategies, such as when they have an invalid or missing ldpc cookie or when they fail the recaptcha test.<br><br><br><br></td></tr></tbody></table>

<br>
