http://xmrhfasfg5suueegrnc4gsgyi2tyclcy5oz7f5drnrodmdtob6t2ioyd.onion/onion-services/advanced/dos/index.html
At your webserver check that clients can set valid cookies, malicious clients often do not have this feature.
In Nginx, Cloudflare provide a library to interact with cookies. Other methods include making sure that clients connecting to your .onion have valid User-Agent header and the Referer header is not set to a value you can associate with the attack.