During the DDoS attack, I noticed that a bunch of /usr/sbin/apache2 -K start processes start and they simply load the server by consuming its RAM until the rest of the processes fall.
Tell me how to solve?
Get rid of it in favor of php-fpm.
Set a reverse proxy and filter on it, discarding all garbage.
It is trite to set it up by setting the number of running processes and the number of clients.
Write to telegram, I can proxy you if the attack is strong.