Not sure if SO is the right forum, but we're in need of help and perhaps programmatic elements may comprise the final solution. Instead of downvoting, please recommend where to post this question, and we'll gladly remove this from SO. Thanks -- we just want to overcome this attack.
It seems like our ecommerce site is under attack from a botnet, causing our site to go down. We're receiving 50-100 requests per second (far surpasses normal traffic). Some requests are for outdated URLs not even normally accessible from the site.
Two questions:
1) How do we confirm if the site is under attack?
2) If the site is under attack, how can we ward off the attack and prevent future ones?
We appreciate any help or guidance anyone can offer.
We're using Tomcat 6.0. (Don't ask why. You don't want to know.)
Thanks!