Rate Limiting
Kong Gateway applies a configured request-rate limit to the protected REST API.
Prevent clients from continuously generating requests above the permitted request rate.
Modern applications and APIs commonly expose REST endpoints that can be accessed repeatedly by clients, automated applications, and other services. If an API does not enforce appropriate request-rate and resource-consumption controls, a client may generate excessive requests and consume disproportionate server resources.
Unrestricted resource consumption can affect CPU utilization, memory consumption, network bandwidth, connection pools, database operations, and application-processing capacity. Repeated high-volume requests can therefore reduce API availability and affect legitimate users.
In this use case, Kong Gateway is deployed as the API gateway protecting a controlled REST API environment on an Ubuntu virtual machine. The REST API provides controlled endpoints that can be accessed through Kong Gateway.
A controlled unrestricted resource consumption assessment is performed from Kali Linux. cURL is used to generate controlled repeated API requests, while OWASP ZAP is used to intercept and analyze API traffic and validate gateway security behavior.
The security assessment focuses on determining whether the Kong Gateway permits unrestricted request consumption when a client repeatedly accesses the protected REST API.
The proposed defensive mechanism implements rate limiting and request resource quotas at the API gateway layer. Kong Gateway limits the number of requests permitted within a defined time period and applies request-level resource restrictions before excessive traffic reaches the backend API.
After implementing the security controls, the resource-consumption assessment is repeated to verify that excessive requests are throttled or rejected while legitimate API requests continue to function.
Kong Gateway is used as the controlled API gateway environment for protecting REST API services and enforcing API traffic-management controls. The gateway receives client requests before forwarding permitted requests to the backend REST API. The protected API therefore depends on gateway-level controls to regulate the amount of traffic that reaches the backend service.
REST APIs become exposed to unrestricted resource consumption when clients can repeatedly send requests without an effective request-rate or resource-consumption policy.
The security problem is therefore:
The proposed solution introduces rate limiting and request resource quotas at the Kong Gateway layer so that excessive requests are controlled before they can continuously consume backend resources.
An unrestricted resource consumption attack attempts to consume excessive application or API resources by generating requests beyond the intended usage level.
In this controlled assessment, the attacker identifies an API endpoint exposed through the Kong Gateway. Repeated requests are generated against the selected REST API endpoint, and the request volume is gradually increased to determine whether the gateway imposes an effective request-rate restriction. The assessment observes whether excessive requests continue to reach the backend service or whether Kong Gateway throttles the traffic.
The primary security concept is to control API traffic at the gateway before excessive requests consume backend application resources.
Kong Gateway evaluates incoming requests against configured traffic-management policies before forwarding them to the protected REST API. Rate limits restrict the number of requests permitted within a defined period, while request quotas control total consumption according to the configured API usage policy.
The secure processing flow is:
Kong Gateway applies a configured request-rate limit to the protected REST API.
Prevent clients from continuously generating requests above the permitted request rate.
A defined request quota is applied to the API or consumer according to the required traffic policy.
Control the total number of requests permitted within the configured quota period.
The gateway evaluates sudden increases in request volume against the configured traffic policy.
Reduce the possibility of short-duration traffic bursts consuming excessive backend resources.
The gateway associates requests with the configured consumer or client identity where applicable.
Apply resource-consumption policies consistently to individual API consumers.
Requests exceeding the configured rate or quota are rejected or throttled at the gateway.
Prevent excessive requests from continuously reaching the backend REST API.
Request-size controls are applied to prevent unnecessarily large requests from consuming excessive processing and memory resources.
Reduce resource consumption caused by oversized API requests.
Appropriate gateway and upstream timeout controls are configured for the protected API.
Prevent slow or excessive requests from holding gateway and backend resources indefinitely.
Requests that exceed the configured traffic policy are recorded through available gateway and application monitoring.
Support investigation of repeated resource-consumption attempts and validate gateway enforcement.
Kong Gateway is used to expose and protect the controlled REST API and enforce request-rate and resource-consumption policies.
OWASP ZAP is used from Kali Linux to intercept and analyze REST API traffic passing through Kong Gateway.
cURL is used to generate controlled repeated requests against the Kong-protected API.
The controlled REST API provides the backend service protected by Kong Gateway.
Ubuntu hosts the Kong Gateway and controlled REST API environment.
Kali Linux is used as the controlled security-testing environment.
VirtualBox provides the isolated laboratory environment for the Ubuntu and Kali Linux virtual machines.