Mailing List Archive

serious dos..
Hi people,

Our network was down the last 12 hours due to an icmp dos attack..something
we would like to see coming next time..instead of looking for broken
routers, blaming our upstream provider and having the telco company
checking the physical connection to the upstream provider ;)

Anyway, i think ntop could do the job..and I was just wondering if people
have experience with using it to monitor realtime up/down streams totals to
mainrouters and to individual hosts behind the routers, as well udp/tcp
traffic as icmp traffic. (and by using it in combination with scripts,
automatic paging or sms-en warnings)...no the web interface.
And on alerting when totall traffic is reaching a limit to the main router,
is it possible to generate somehow a more detailed report of who is taking
up the resources?
Are there any example configs/rules which people are willing to share?
I hope so..would get me in the right direction.

Thx

Frank
Re: serious dos.. [ In reply to ]
Hello Frank,

Saturday, 09 June 2001, you wrote:


F> Hi people,

F> Our network was down the last 12 hours due to an icmp dos attack..something
F> we would like to see coming next time..instead of looking for broken
F> routers, blaming our upstream provider and having the telco company
F> checking the physical connection to the upstream provider ;)

F> Anyway, i think ntop could do the job..and I was just wondering if people
F> have experience with using it to monitor realtime up/down streams totals to
F> mainrouters and to individual hosts behind the routers, as well udp/tcp
F> traffic as icmp traffic. (and by using it in combination with scripts,
F> automatic paging or sms-en warnings)...no the web interface.
F> And on alerting when totall traffic is reaching a limit to the main router,
F> is it possible to generate somehow a more detailed report of who is taking
F> up the resources?
F> Are there any example configs/rules which people are willing to share?
F> I hope so..would get me in the right direction.

I've used the realtime portion of ntop to identify a 'DoS in
progress' to our IRC server and where it was coming from. Using
the information ntop provided (amongst other sources) I was
a) able to cobble together some quick border router rules, b) get
our upstream provider to block this host temporarily and c) got
said attacker's cable service revoked.

While it is capable of doing what you initially ask of it, I'm not
sure your detailed requirements can be met.

Anyone else?



Best Regards,

Lee Smallbone

+----------------------------------------------+
| Kechara Internet - Global Reach, Local Touch |
+----------------------------------------------+
| Sales: 0800 138 7727 | Support: 01243 869969 |
| sales@kechara.net | support@kechara.net |
| web: www.kechara.net | Intl: +44 1243 869969 |
+----------------------------------------------+