Solved

This output is given from : sflowtool -4 -p 3601  | /scripts/DoSTargets

Posted on 2013-12-21
2
392 Views
Last Modified: 2013-12-22
I have 2 databases
1. ip.whitelist have only one column with ip name
2. ip.Block have 3 columns ip,reason,zaman

i have a sample output on flow as given below

sflowtool -4 -p 3601  | /scripts/DoSTargets


1387652837 178.20.228.47 15 mbps
1387652837 178.20.228.47 1792 pps
1387652837 185.9.156.35 11 mbps
1387652837 185.9.159.233 1536 pps
1387652838 185.9.156.35 11 mbps
1387652839 178.20.228.47 26 mbps
1387652839 178.20.228.47 2560 pps
1387652839 85.100.207.114 8 mbps
1387652840 178.20.228.47 27 mbps
1387652840 178.20.228.47 3072 pps
1387652840 185.9.159.233 12 mbps
1387652840 185.9.159.233 2304 pps
1387652841 178.20.228.47 20 mbps
1387652841 178.20.228.47 2048 pps
1387652841 89.253.155.97 8 mbps
1387652842 178.20.228.47 20 mbps
1387652842 178.20.228.47 1792 pps
1387652843 178.20.228.47 15 mbps
1387652843 178.20.228.47 1792 pps

Open in new window




i want sth. like this.

sflowtool -4 -p 3601  | /scripts/DoSTargets  | perl DDOSrecorder.pl

and if the traffic is bigger then 100mbps or 25000 pps it will check the ip.whitelist
and if it is not in white listed table it will only add the ip address to the ip.block table
reason column will only include the Xmbps or Xpps  to understand the blocking
0
Comment
Question by:3XLcom
2 Comments
 
LVL 84

Accepted Solution

by:
ozo earned 500 total points
ID: 39735081
my %X=(
mbps => 100,
pps => 25000,
);
open W,"<ip.whitelist" or die "<ip.whitelist $!";
chomp,++$w{$_} while <W>;
close W;
open STDOUT,">>ip.block" or die ">>ip.block $!";
while( <> ){
  my @F=split;
  print "$F[1,2,3]\n" if !$w{$F[1]} && $F[2]>$X{$F[3]};
}
0
 

Author Closing Comment

by:3XLcom
ID: 39735095
thnx
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have been pestered over the years to produce and distribute regular data extracts, and often the request have explicitly requested the data be emailed as an Excel attachement; specifically Excel, as it appears: CSV files confuse (no Red or Green h…
A year or so back I was asked to have a play with MongoDB; within half an hour I had downloaded (http://www.mongodb.org/downloads),  installed and started the daemon, and had a console window open. After an hour or two of playing at the command …
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question