Skip to main content
100%

Gist 7bad13b3f760c4afa2f3

✓ Published0🌍 Public
CCBasis
Last edited Oct 29, 2011
Created on Sep 17, 2014

This example shows how to analyze and mitigate a SYN flood attack against a web server, where the attacker opens many TCP connections without sending data. The visualization consists of command-line output and shell scripts, not a graphical chart, and it presents the sequence of diagnostic and defensive steps. The code uses standard Unix tools like `netstat`, `awk`, `sort`, `uniq`, and `cut` to count connections per state and per source IP, as well as `whois` for IP lookup. It also demonstrates `ulimit` to raise the file descriptor limit, `iptables` with the `connlimit` module to cap per-host connections, and the `lighttpd` init script to restart the server. The approach is purely textual, showing the raw commands and their expected outputs.

AI-generated description

Similar vizzes