ddos-sim.com All simulations Configure a test
Home › DDoS simulation testing › SSL/TLS exhaustion test

Layer 6 · Presentation · tls_exhaustion_check

SSL/TLS exhaustion test

The tls_exhaustion_check simulation completes a full TLS handshake per operation to expose the crypto cost of handshake pressure on a domain you own. It targets the asymmetric expense of setting up encryption — cheap for a client, costly for your server.

Layer L6 Protocol TLS Command tls_exhaustion_check Access After verification

On this page

  1. What a TLS handshake flood does
  2. How ddos-sim.com simulates it safely
  3. What the test exercises
  4. How to run the test
  5. Availability & limits
  6. FAQ
  7. Related simulations

What a TLS handshake flood does

A TLS exhaustion attack forces the server to perform the expensive part of the handshake — key exchange and signing — over and over, often abandoning each session right after. The asymmetry is the weapon: a client spends little, while the server burns CPU on every negotiation, so a modest request rate can saturate a termination node.

How ddos-sim.com simulates it safely

ddos-sim.com completes a genuine, full TLS handshake per operation against a single verified domain pinned to a public address, within the rate and concurrency limits for that domain. It measures real negotiation cost without spoofing or malformed handshakes.

Authorized targets only

Every run is bound to one verified domain you have proven you own. Ownership is checked over DNS or HTTPS before anything is scheduled, and running traffic against systems you do not own or are not clearly authorized to test may be unlawful. See the Acceptable Use Policy.

What the test exercises

  • CPU cost of key exchange and certificate signing
  • TLS termination and offload capacity
  • Session-resumption and ticket effectiveness
  • Scaling of the termination tier under handshake pressure
  • Cipher-suite choices and their compute cost

How to run a ssl/tls exhaustion test

  1. Verify your domain. Prove ownership over DNS or HTTPS — it is self-service and takes minutes.
  2. Add the tls_exhaustion_check command to a timeline in the portal and set the target path or port, rate, and duration.
  3. Set health thresholds. Choose the error-rate, latency, or status-code limits at which the test should abort itself.
  4. Run and watch. Bounded workers are provisioned minutes before start and torn down the moment the last task ends, while metrics stream live.
  5. Read the results. Review the recorded latency, status codes, and worker timeline to find where your service starts to bend.

Configure a ssl/tls exhaustion test in the portal →

Availability & limits

SSL/TLS exhaustion tests are available after self-service domain verification and run with prepaid credits.

Frequently asked questions

What mitigations does this test typically point to?

Enabling session resumption and TLS tickets, offloading termination to a CDN or dedicated hardware, choosing efficient cipher suites, and scaling the termination tier independently of the application.

How is it different from an HTTPS check?

The HTTPS check measures whole-request behavior over TLS, while tls_exhaustion focuses on the handshake itself to isolate the CPU cost of repeated negotiation.

Related simulations

HTTPS resilience test https_check Run an authorized HTTPS resilience test against a domain you own. Slowloris test slowloris_check Simulate a Slowloris slow-HTTP attack against a domain you own. HTTP/2 Rapid Reset test (CVE-2023-44487) http2_rapid_reset Test your servers against the HTTP/2 Rapid Reset attack (CVE-2023-44487).

Rehearse the ssl/tls exhaustion against infrastructure you own — bounded, monitored, and stopped the instant you have your answer.

Configure a test
← All DDoS simulations
© 2026 ddos-sim.com · Authorized testing only. Simulations · Terms · Acceptable use · Privacy