Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Solutions in APEX against DDoS, HTTP Flood attacks?

KalmanVFeb 18 2025

Hi,

We have encountered malicious load-based attacks (DDoS, HTTP Flood) in recent days, affecting an APEX application that includes public pages. As a result, thousands of new SESSION_IDs were generated in APEX.

How can such attacks be mitigated or prevented?   
How can we ensure that APEX does not create a new SESSION\_ID unless authentication is successful?  
Would it be advisable to place public pages in a separate application, isolating them from non-public pages?   
What settings should be applied in Shared Components, specifically in Security Attributes and Authentication Schemes?

I look forward to all ideas.

Best regards:

Kalman Viktor

Comments
Post Details
Added on Feb 18 2025
3 comments
186 views