It wont work well, as LSWS does not know which vhost a connection goes to without accepting the connection and receiving the request headers, there is no way to tell which connection is valid user, which one is from attacker, if close connections after accepting connections, valid user will be affected.