Back to articles
Technology Insight

Building an Automated Anti-Scraping System: Combining CrowdSec and OpenResty on a VPS to Block Bad Bots

May 30, 2026

Introduction: The Growing Threat of Malicious Web Scraping

In the modern digital economy, data is one of the most valuable assets a business possesses. However, this value also makes it a prime target for automated exploitation. While legitimate bots like Googlebot are essential for search engine visibility, a massive influx of 'Bad Bots' operates in the shadows. These malicious scripts continuously scrape proprietary data, harvest pricing intelligence, steal copyrighted content, and aggressively drain server resources.

For businesses hosting applications on Virtual Private Servers (VPS), standard rate limiting or static IP blacklisting is no longer sufficient. Sophisticated scraping networks utilize distributed residential proxies to bypass traditional defenses. To protect your digital infrastructure without degrading the experience of legitimate users, you need a dynamic, real-time intrusion prevention system. This guide provides a comprehensive framework for building an automated anti-scraping system by combining OpenResty—a high-performance web platform built on Nginx—with CrowdSec, a modern, collaborative security engine.

Understanding the Architecture: Why OpenResty and CrowdSec?

Before diving into the technical implementation, it is crucial to understand why this specific combination of open-source tools provides an elite defense mechanism against automated threats.

  • OpenResty (The Gatekeeper): OpenResty integrates the standard Nginx core with powerful Lua modules. This allows developers to execute lightweight Lua scripts directly inside the Nginx worker processes. By handling access control at the web server level before requests ever reach your application backend (such as PHP, Node.js, or Python), you achieve maximum throughput and minimal latency.
  • CrowdSec (The Brain): CrowdSec is a behavior-based security engine that analyzes server logs in real-time to detect anomalous patterns. Unlike traditional tools like Fail2ban, which rely purely on local regex matching, CrowdSec utilizes a decentralized, crowdsourced intelligence network. When a bad bot is blocked on one server, its IP reputation is shared across the entire CrowdSec ecosystem, protecting your VPS proactively.

By leveraging an OpenResty Lua plugin connected to the CrowdSec Local API (LAPI), we can inspect every incoming request against a real-time database of malicious actors, blocking them instantly at the network edge with negligible CPU overhead.

Step 1: Installing and Configuring OpenResty

To begin, we must replace standard Nginx with OpenResty on your VPS. OpenResty provides the necessary Lua ecosystem natively, eliminating the need to compile complex Nginx modules from scratch.

1.1 Add the Official OpenResty Repository

Log in to your VPS via SSH as a privileged user and execute the following commands to add the repository (example based on Ubuntu/Debian systems):

sudo apt-get update sudo apt-get install -y wget gnupg software-properties-common wget -qO - [https://openresty.org/package/pubkey.gpg](https://openresty.org/package/pubkey.gpg) | sudo apt-key add - sudo add-apt-repository -y "deb [http://openresty.org/package/debian](http://openresty.org/package/debian) $(lsb_release -sc) openresty"

1.2 Install the Package

Update your package lists and install OpenResty along with the standard development tools:

sudo apt-get update sudo apt-get install -y openresty

Once installed, verify that OpenResty is running successfully by checking its systemd service status: sudo systemctl status openresty.

Step 2: Deploying the CrowdSec Security Engine

Next, we will install the CrowdSec daemon on the same VPS. CrowdSec will monitor OpenResty's access logs to detect bad behaviors such as directory brute-forcing, aggressive crawling, or application scanning.

2.1 Install CrowdSec via Official Script

Execute the official installation script to configure repositories and download the security engine:

curl -s [https://install.crowdsec.net](https://install.crowdsec.net) | sudo bash sudo apt-get install crowdsec -y

2.2 Install the Nginx/OpenResty Collection

CrowdSec uses "collections"—pre-configured sets of parsers and scenarios—to understand specific log formats. Install the Nginx collection to immediately enable detection capabilities for web threats:

sudo cscli collections install crowdsecurity/nginx sudo systemctl restart crowdsec

At this stage, CrowdSec is actively reading your server logs and calculating risk scores for incoming traffic based on localized behavior rules.

Step 3: Integrating OpenResty with the CrowdSec LAPI Bouncer

To actively block bad bots rather than just logging their existence, we must bridge OpenResty and CrowdSec. This is achieved using the CrowdSec OpenResty Remediation Component (Bouncer), which utilizes Lua to query CrowdSec's Local API before serving any web page.

3.1 Install the OpenResty Bouncer

Download and install the dedicated Lua bouncer package for OpenResty:

sudo apt-get install lua-resty-http sudo apt-get install crowdsec-openresty-bouncer

3.2 Generate an API Key

Generate a secure Local API key so that the OpenResty bouncer can securely communicate with the CrowdSec daemon:

sudo cscli bouncers add openresty-bouncer-vps

Note: Copy the generated API token immediately; you will need to paste it into the configuration file in the next step.

3.3 Configure the Lua Plugin

Open the bouncer configuration file located at /etc/crowdsec/bouncers/crowdsec-openresty-bouncer.conf and update the following directives:

API_URL=[http://127.0.0.1:8080](http://127.0.0.1:8080) API_KEY=YOUR_GENERATED_API_KEY BOUNCING_ON_TYPE=ban

Step 4: Crafting Custom Scenarios to Detect Aggressive Scraping

While CrowdSec includes general web protection, scrapers often operate just below standard rate limits. To catch dedicated bad bots, we need to implement a custom rule specifically targeting rapid, non-human content harvesting.

4.1 Create a Custom Anti-Scraping Scenario

Create a new configuration file at /etc/crowdsec/scenarios/vps-anti-scraping.yaml:

type: leaky_bucket name: company/vps-anti-scraping description: "Detect aggressive data scraping patterns" filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.static_image == 'false'" leakspeed: 2/s capacity: 30 groupeby: evt.Meta.source_ip blackhole: 5m labels: remediation: true scope: ip

This configuration utilizes a leaky bucket algorithm. If an IP address requests more than 30 pages within a highly condensed window (leaking at 2 requests per second), the scenario triggers. The malicious IP is instantly categorized for remediation, and the OpenResty bouncer will immediately serve a 403 Forbidden or a CAPTCHA wall to that specific user.

Apply the new rules by restarting the service: sudo systemctl restart crowdsec.

Step 5: Testing and Monitoring the Defense Matrix

To ensure your automated system works flawlessly without disrupting legitimate corporate traffic or search engines, comprehensive verification is necessary.

5.1 Simulating a Scraping Attack

You can simulate an automated scraping attack from a separate machine using an aggressive benchmarking tool like ApacheBench (ab) or a custom Python script:

ab -n 200 -c 10 http://your-vps-ip/index.html

5.2 Inspecting the Blocks

Return to your VPS terminal and execute the CrowdSec command-line interface tool to verify that the attacking IP has been systematically banned:

sudo cscli decisions list

The output will display a structured table showing the offending IP, the specific scenario triggered (e.g., company/vps-anti-scraping), the remediation type applied (ban), and the exact time remaining on the expiration timer.

Conclusion: Proactive Enterprise Security on a Budget

Implementing a manual IP blocklist is a reactive, losing battle against modern web automation. By uniting the raw performance of OpenResty with the crowdsourced, behavioral intelligence of CrowdSec, you establish an enterprise-grade web application firewall (WAF) directly on your VPS. This architecture guarantees that data scraping attempts are minimized, server resource utilization remains predictable, and proprietary business insights remain securely protected from unauthorized automated harvesting. Continuous optimization of your custom scenarios will ensure that your defense system remains resilient against the evolving tactics of malicious actors.

Building an Automated Anti-Scraping System: Combining CrowdSec and OpenResty on a VPS to Block Bad Bots | DPTCloud