Re: calculate "new connections per second" (nfcan: addressed to exclusive sender for this address)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Thanks for the reply Jim.

I am using the ip_conntrack module to mark connections on a linux bridge to 
shape traffic. Sometimes if there is a DOS attack the ip_conntrack table 
overflows and the kernel starts dropping packets.  I want to measure the rate 
at which the connections are being made and being entered in the ip_conntrack 
table so if there is a spike in the rate I will know that there is a DOS 
attack going on.  I hope you can now understand my situation. I you need more 
information please let me know.

Appreciate your help.

Regards,
Gaurav.

On Wednesday 15 March 2006 23:32, Jim Laurino wrote:
> On 2006.03.15 10:13, Gaurav Sharma - gaurav@xxxxxxxxxxxxxx wrote:
> > Hello,
> >
> > I am trying to find out a way to calculate
> > the rate of "new connections per second"
> > for the ip_conntrack module.
> > What would be a good approach for this problem?
>
> Are you asking how to determine
> the time each connection is established
> or are you asking, given this data,
> how to estimate this rate.
>
> Can you explain how you want to use the measurement?


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux