Now trying the TCP plugin in Munin...
It looks like useful to watch later/archive on a graph all TCP connections.
Not 100% logging those attacks, but if those bad guys are using TCP I think it will be shown here...
Here an example on my relay, graph activated ~24h ago :

TCP


Le 14/06/2016 à 14:59, Petrusko a écrit :
Hey,

Little noob question inside :)
If possible to learn quickly how to detect a DDOS attack ?

I got Munin running behind, can it be useful with the "netstat" and
"firewall throughput" plugins graphs to see it ?
So if the server is attacked, I think it will show some big spikes in
those graphs...?

Thx ;)

ps: I'll try to find some things about this subject, np!



Le 14/06/2016 07:03, Markus Koch a écrit :
4 of my 5 tor servers are under a incoming DDOS attack. Am I the only
one or is anyone else feeling the "love"?

Markus
_______________________________________________
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays


_______________________________________________
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays

-- 
Petrusko
PubKey EBE23AE5
C0BF 2184 4A77 4A18 90E9 F72C B3CA E665 EBE2 3AE5