Location Research Breakthrough Possible @S-Logix pro@slogix.in

Throttling Unrestricted Resource Consumption Attacks Against Kong Gateway-Protected REST APIs Through Rate Limiting and Request Resource Quotas

Description

Modern applications and APIs commonly expose REST endpoints that can be accessed repeatedly by clients, automated applications, and other services. If an API does not enforce appropriate request-rate and resource-consumption controls, a client may generate excessive requests and consume disproportionate server resources.

Unrestricted resource consumption can affect CPU utilization, memory consumption, network bandwidth, connection pools, database operations, and application-processing capacity. Repeated high-volume requests can therefore reduce API availability and affect legitimate users.

In this use case, Kong Gateway is deployed as the API gateway protecting a controlled REST API environment on an Ubuntu virtual machine. The REST API provides controlled endpoints that can be accessed through Kong Gateway.

A controlled unrestricted resource consumption assessment is performed from Kali Linux. cURL is used to generate controlled repeated API requests, while OWASP ZAP is used to intercept and analyze API traffic and validate gateway security behavior.

The security assessment focuses on determining whether the Kong Gateway permits unrestricted request consumption when a client repeatedly accesses the protected REST API.

The proposed defensive mechanism implements rate limiting and request resource quotas at the API gateway layer. Kong Gateway limits the number of requests permitted within a defined time period and applies request-level resource restrictions before excessive traffic reaches the backend API.

After implementing the security controls, the resource-consumption assessment is repeated to verify that excessive requests are throttled or rejected while legitimate API requests continue to function.

Existing Security Problem

Application: Kong Gateway-Protected REST APIs

Kong Gateway is used as the controlled API gateway environment for protecting REST API services and enforcing API traffic-management controls. The gateway receives client requests before forwarding permitted requests to the backend REST API. The protected API therefore depends on gateway-level controls to regulate the amount of traffic that reaches the backend service.

Existing Problem:

REST APIs become exposed to unrestricted resource consumption when clients can repeatedly send requests without an effective request-rate or resource-consumption policy.

The security problem is therefore:

Kong Gateway-Protected REST API → No Effective Request Rate Restriction → Repeated High-Volume API Requests → Excessive Backend Request Processing → Increased CPU / Memory / Connection Consumption → Reduced API Processing Capacity → Legitimate Request Delays or Rejection → API Availability and Resource-Consumption Risk

The proposed solution introduces rate limiting and request resource quotas at the Kong Gateway layer so that excessive requests are controlled before they can continuously consume backend resources.

Attack

Specific Attack: Unrestricted Resource Consumption

An unrestricted resource consumption attack attempts to consume excessive application or API resources by generating requests beyond the intended usage level.

In this controlled assessment, the attacker identifies an API endpoint exposed through the Kong Gateway. Repeated requests are generated against the selected REST API endpoint, and the request volume is gradually increased to determine whether the gateway imposes an effective request-rate restriction. The assessment observes whether excessive requests continue to reach the backend service or whether Kong Gateway throttles the traffic.

Attack Behavior:
Protected REST API Endpoint Identified
→
Normal API Request Established
→
Repeated API Requests Generated
→
Request Rate Increased
→
Kong Gateway Receives High-Volume Traffic
→
No Effective Rate Restriction
→
Excessive Requests Forwarded to Backend
→
Backend Resource Consumption Increases
→
API Processing Capacity Reduced
→
Resource Consumption Security Risk

Security Concept

API Rate Limiting and Resource Quota Enforcement:

The primary security concept is to control API traffic at the gateway before excessive requests consume backend application resources.

Kong Gateway evaluates incoming requests against configured traffic-management policies before forwarding them to the protected REST API. Rate limits restrict the number of requests permitted within a defined period, while request quotas control total consumption according to the configured API usage policy.

The secure processing flow is:

Client Request
→
Request Identification
→
Rate-Limit Evaluation
→
Resource-Quota Evaluation
→
Request Allowed / Request Throttled
→
Backend API

Defensive Mechanism

Rate Limiting

Kong Gateway applies a configured request-rate limit to the protected REST API.

Purpose

Prevent clients from continuously generating requests above the permitted request rate.

Request Quota Enforcement

A defined request quota is applied to the API or consumer according to the required traffic policy.

Purpose

Control the total number of requests permitted within the configured quota period.

Burst Request Control

The gateway evaluates sudden increases in request volume against the configured traffic policy.

Purpose

Reduce the possibility of short-duration traffic bursts consuming excessive backend resources.

Consumer Identification

The gateway associates requests with the configured consumer or client identity where applicable.

Purpose

Apply resource-consumption policies consistently to individual API consumers.

Gateway-Level Request Rejection

Requests exceeding the configured rate or quota are rejected or throttled at the gateway.

Purpose

Prevent excessive requests from continuously reaching the backend REST API.

Request Size Restriction

Request-size controls are applied to prevent unnecessarily large requests from consuming excessive processing and memory resources.

Purpose

Reduce resource consumption caused by oversized API requests.

Connection and Timeout Controls

Appropriate gateway and upstream timeout controls are configured for the protected API.

Purpose

Prevent slow or excessive requests from holding gateway and backend resources indefinitely.

Rate-Limit Event Monitoring

Requests that exceed the configured traffic policy are recorded through available gateway and application monitoring.

Purpose

Support investigation of repeated resource-consumption attempts and validate gateway enforcement.

Security Tools

Primary API Gateway Protection Tool: Kong Gateway

Kong Gateway is used to expose and protect the controlled REST API and enforce request-rate and resource-consumption policies.

Purpose
  • Protect REST API endpoints.
  • Apply rate-limiting policies.
  • Apply request-consumption quotas.
  • Throttle excessive API traffic.
  • Reject requests exceeding configured limits.
  • Forward permitted requests to the backend service.
  • Validate post-remediation API behavior.

API Security Testing Tool: OWASP ZAP

OWASP ZAP is used from Kali Linux to intercept and analyze REST API traffic passing through Kong Gateway.

Purpose
  • Capture API requests.
  • Identify protected REST API endpoints.
  • Replay API requests.
  • Analyze rate-limit responses.
  • Observe throttling behavior.
  • Compare API behavior before and after remediation.

HTTP Request Testing Tool: cURL

cURL is used to generate controlled repeated requests against the Kong-protected API.

Purpose
  • Send legitimate API requests.
  • Generate repeated requests.
  • Increase request volume in a controlled manner.
  • Observe HTTP responses.
  • Validate rate-limit enforcement.
  • Verify post-remediation request behavior.

Target Application: REST API

The controlled REST API provides the backend service protected by Kong Gateway.

Purpose
  • Provide API endpoints for testing.
  • Process legitimate requests.
  • Receive permitted traffic from Kong Gateway.
  • Demonstrate backend resource consumption.
  • Validate the effectiveness of gateway-level controls.

Server Environment: Ubuntu

Ubuntu hosts the Kong Gateway and controlled REST API environment.

Purpose
  • Run the API gateway.
  • Host the backend REST API.
  • Maintain gateway configuration.
  • Monitor application and gateway activity.
  • Validate resource-consumption controls.

Security Testing Environment: Kali Linux

Kali Linux is used as the controlled security-testing environment.

Purpose
  • Run cURL.
  • Run OWASP ZAP.
  • Generate controlled API traffic.
  • Analyze gateway responses.
  • Perform resource-consumption security testing.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated laboratory environment for the Ubuntu and Kali Linux virtual machines.

Purpose
  • Create isolated virtual machines.
  • Provide controlled network communication.
  • Separate the API server and security-testing environment.
  • Maintain a reproducible API security-testing laboratory.

Process

STEP 01

Step 1: Prepare the Virtualized API Security Environment

  • Create an isolated cybersecurity laboratory using VirtualBox.
  • Configure Ubuntu as the Kong Gateway and REST API server environment.
  • Configure Kali Linux as the security-testing environment.
  • Configure the virtual network to allow controlled communication between the two virtual machines.
  • Verify connectivity between Kali Linux and Ubuntu.
  • Confirm that Kali Linux can reach the Kong Gateway.
  • Ensure that the testing environment does not target external systems.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Step 2: Prepare the REST API Environment

  • Install and configure the controlled REST API on Ubuntu.
  • Create the required API endpoint for testing.
  • Configure the backend service to listen on the required interface and port.
  • Start the REST API service.
  • Verify that the backend API responds correctly.
  • Confirm normal API functionality before introducing Kong Gateway.
Tools: Ubuntu + REST API
STEP 03

Step 3: Deploy and Configure Kong Gateway

  • Install and configure Kong Gateway on the Ubuntu environment.
  • Configure Kong Gateway to operate as the entry point for the REST API.
  • Verify that Kong Gateway is running correctly.
  • Configure the required gateway listener.
  • Confirm that the gateway can communicate with the backend REST API.
  • Verify the gateway status before security testing.
Tools: Ubuntu + Kong Gateway
STEP 04

Step 4: Register the REST API with Kong Gateway

  • Configure the REST API as an upstream service in Kong Gateway.
  • Create the required Kong Gateway service configuration.
  • Configure a route that exposes the REST API through the gateway.
  • Verify that requests sent to the gateway are forwarded to the backend API.
  • Confirm that the backend service is not directly required for normal client access.
  • Establish the normal gateway-to-backend request flow.
Tools: Kong Gateway + REST API + Ubuntu
STEP 05

Step 5: Establish Normal API Request Behavior

  • Send legitimate REST API requests through Kong Gateway.
  • Verify that Kong Gateway accepts the requests.
  • Confirm that the requests reach the backend REST API.
  • Observe the API response.
  • Record the normal response status and processing behavior.
  • Establish the baseline for legitimate API traffic.
Tools: Kali Linux + cURL + Kong Gateway + REST API
STEP 06

Step 6: Capture and Analyze API Traffic

  • Configure OWASP ZAP as the API testing proxy.
  • Route controlled REST API traffic through OWASP ZAP.
  • Capture requests sent toward the Kong Gateway.
  • Identify the protected API endpoint.
  • Inspect request and response behavior.
  • Record the normal traffic pattern before resource-consumption testing.
Tools: Kali Linux + OWASP ZAP + Kong Gateway
STEP 07

Step 7: Identify the Resource-Consumption Attack Surface

  • Identify REST API endpoints that can repeatedly process requests.
  • Determine which endpoints perform meaningful backend processing.
  • Identify endpoints that can be accessed repeatedly by the same client.
  • Observe the response time and response behavior under normal request volume.
  • Determine the request path from the client through Kong Gateway to the backend.
  • Document the API resource-consumption attack surface.
Tools: OWASP ZAP + Kong Gateway + REST API
STEP 08

Step 8: Perform Controlled Repeated-Request Testing

  • Send repeated requests to the selected REST API endpoint.
  • Maintain the requests within the controlled laboratory environment.
  • Observe whether Kong Gateway forwards every request to the backend.
  • Record the number of requests successfully processed.
  • Monitor response status codes and response timing.
  • Establish how the API behaves when request volume increases.
Tools: Kali Linux + cURL + Kong Gateway
STEP 09

Step 9: Increase Controlled Request Volume

  • Gradually increase the number of requests sent to the protected API.
  • Observe the gateway response as the request rate increases.
  • Determine whether requests continue reaching the backend without restriction.
  • Monitor the API response behavior.
  • Observe CPU, memory, and request-processing activity on the Ubuntu environment.
  • Record the request volume at which resource consumption becomes noticeable.
Tools: Kali Linux + cURL + Ubuntu + Kong Gateway
STEP 10

Step 10: Confirm the Unrestricted Resource Consumption Condition

  • Repeat the controlled high-volume request assessment.
  • Compare normal API traffic with increased request traffic.
  • Determine whether Kong Gateway allows excessive requests without effective throttling.
  • Identify whether excessive requests continue reaching the backend.
  • Record the observed resource-consumption behavior.
  • Document the affected API endpoint and traffic condition.
  • Confirm the resource-consumption weakness before remediation.
Tools: cURL + OWASP ZAP + Kong Gateway + Ubuntu
STEP 11

Step 11: Configure Kong Gateway Rate Limiting

  • Configure the appropriate Kong Gateway Rate Limiting policy for the protected API.
  • Define the permitted request rate.
  • Configure the required rate-limiting period.
  • Associate the policy with the appropriate API service, route, or consumer.
  • Apply the rate-limiting configuration.
  • Verify that Kong Gateway loads the configuration successfully.
  • Prepare the gateway for controlled rate-limit validation.
Tools: Ubuntu + Kong Gateway
STEP 12

Step 12: Configure Request Resource Quotas

  • Define the permitted request-consumption quota for the protected API.
  • Configure the quota according to the intended API usage policy.
  • Associate the quota with the appropriate API consumer or protected route where applicable.
  • Ensure that quota enforcement is applied at the gateway layer.
  • Verify the configured resource-consumption policy.
  • Confirm that excessive request consumption will be controlled before reaching the backend.
Tools: Ubuntu + Kong Gateway
STEP 13

Step 13: Configure Request Size and Processing Controls

  • Configure appropriate request-size restrictions for the protected API.
  • Prevent unnecessarily large request bodies from consuming excessive resources.
  • Configure suitable upstream timeout values.
  • Review gateway request-processing limits.
  • Ensure that resource-intensive request conditions are controlled.
  • Verify that legitimate API requests remain within the configured limits.
Tools: Kong Gateway + Ubuntu + REST API
STEP 14

Step 14: Configure Excessive-Request Handling

  • Configure Kong Gateway to reject or throttle requests that exceed the configured rate.
  • Verify the response generated when the rate limit is exceeded.
  • Ensure that excessive requests do not continuously reach the backend.
  • Configure appropriate client-facing rate-limit responses.
  • Verify that the API does not expose unnecessary internal gateway information.
  • Record rate-limit enforcement events through available monitoring.
Tools: Kong Gateway + Ubuntu
STEP 15

Step 15: Re-Test High-Volume API Requests After Remediation

  • Send the same controlled repeated requests used during the initial assessment.
  • Gradually increase the request rate.
  • Observe the Kong Gateway response.
  • Verify that requests exceeding the configured limit are throttled or rejected.
  • Confirm that excessive traffic is stopped at the gateway.
  • Compare the post-remediation results with the original unrestricted behavior.
Tools: Kali Linux + cURL + Kong Gateway
STEP 16

Step 16: Validate Request Resource Quotas

  • Generate controlled API requests until the configured request quota is approached.
  • Continue the controlled request sequence within the laboratory.
  • Observe the gateway response when the quota is reached.
  • Verify that additional requests are throttled or rejected according to the configured policy.
  • Confirm that excessive requests are not continuously forwarded to the backend.
  • Record the quota-enforcement behavior.
Tools: Kali Linux + cURL + Kong Gateway
STEP 17

Step 17: Validate Legitimate API Requests

  • Send normal API requests using the permitted request rate.
  • Verify that legitimate requests continue to reach the backend.
  • Confirm that the API returns the expected responses.
  • Ensure that the rate-limiting configuration does not unnecessarily block normal usage.
  • Verify that permitted consumers can continue accessing the API.
  • Compare legitimate API behavior before and after remediation.
Tools: Kali Linux + cURL + Kong Gateway + REST API
STEP 18

Step 18: Perform Final API Resource-Consumption Validation

  • Perform a final resource-consumption security assessment using OWASP ZAP.
  • Repeat controlled high-volume API testing using cURL.
  • Re-test the configured request-rate limit.
  • Re-test the request quota.
  • Re-test request-size restrictions.
  • Verify excessive-request throttling or rejection.
  • Monitor backend resource behavior during the assessment.
  • Verify that legitimate API traffic continues to function.
  • Review gateway and application logs for rate-limit events.
  • Document the final resource-consumption security results.
Tools: OWASP ZAP + cURL + Kong Gateway + REST API + Ubuntu
STEP 19

Step 19: Document the Final Security Assessment

  • Document the original unrestricted resource-consumption behavior.
  • Record the affected REST API endpoint.
  • Document the observed high-volume request behavior.
  • Record the configured rate-limiting policy.
  • Document the request resource-quota configuration.
  • Record the post-remediation throttling and rejection results.
  • Confirm that excessive requests are controlled at Kong Gateway.
  • Confirm that legitimate API requests remain functional.
  • Maintain the final assessment as evidence of the completed resource-consumption security validation.
Tools: Kong Gateway + OWASP ZAP + cURL + Ubuntu + Kali Linux

Outcome

  1. The unrestricted resource consumption vulnerability is assessed against the controlled Kong Gateway-protected REST API environment.
  2. The assessment demonstrates the security risk created when REST API clients can continuously generate requests without effective resource-consumption controls.
  3. The protected REST API and its gateway request-processing path are identified and analyzed.
  4. Controlled high-volume API requests are generated to evaluate the resource-consumption behavior of the protected service.
  5. Kong Gateway rate limiting is implemented to restrict requests that exceed the configured request rate.
  6. Configured request resource quotas control excessive request consumption within the defined policy period.
  7. Excessive API requests are throttled or rejected at the gateway before they can continuously consume backend resources.
  8. Request-size and processing controls provide additional protection against resource-intensive API requests.
  9. Legitimate API requests continue to function within the configured traffic limits.
  10. Gateway and application security events provide visibility into excessive-request and rate-limit activity.
  11. Kong Gateway, OWASP ZAP, cURL, Ubuntu, Kali Linux, and the controlled REST API are used to demonstrate the complete resource-consumption attack assessment, defensive implementation, and post-remediation security-validation workflow.
← Previous Project
Project 7 of 7