V
V
Vit2017-01-31 16:38:15
linux
Vit, 2017-01-31 16:38:15

Where to look for traces of DDoS?

According to uptimerobot, the server (CentOS) was downtime for 18 minutes. Sometimes there are ddos ​​attacks, but this time there is nothing in the logs. How to find the reason why the server was not responding?
I looked at the nginx and apache logs. There is a request at 9:23, then immediately at 9:41. It is not clear what the server was doing at that time? Is there a way to find out the reason?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
Alexey, 2017-01-31
@reech

After the fact, without special utilities, such things are extremely difficult to establish. One and a half gigabits of UDP flood could fly to you, which the server could not process with all the desire (not even because of ksoftirqd, but simply because the interfaces do not hold so much or the provider's channel already). But in general, a strange DDoS for 15 minutes, this is unjustified and not necessary, except perhaps as a test of the pen before real problems.
Pull the TP, let them look at the stats on the interfaces and other diagnostics if this is not available to you. In the meantime, she answers, configure atop, sar, anything you like, just to collect diagnostics and add them to a file. Then, after recovery, it will be possible to raise the history and track what happened. atop has a convenient ncurses interface, sar collects very deep diagnostics.

Y
Yuri Chudnovsky, 2017-01-31
@Frankenstine

If the logs are empty, there was probably simply no Internet.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question