awk, cut, sort, uniq 隞, 臭誑啣箸 ip 蝺賊, 銝衣券蝺賊摨勗撠, 隞乩撠 TCP ESTABLISHED 蝺瑼X:- netstat -an|grep ESTABLISHED|awk '/^tcp/ {print $5}'|awk -F: '{print $1}'|sort|uniq -c|sort -nr|more
銴鋆賭誨蝣 撠 port 80 蝺, 撠瘥 ip 蝺賊啣箔蒂脰摨:- netstat -ntu | grep :80 | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr|more
銴鋆賭誨蝣 箸憭交貊 10 IP 園交賂嗡葉 :80 舫亙嚗舀寞唾瑼X亦- netstat -atnp -A inet | grep ":80" | awk -F " " '{print $5}' | awk -F ":" '{print $1}' | sort | uniq -c | sort -nr | head -10
銴鋆賭誨蝣
, T/ s8 W; x) o5 l* i7 \( N/ Y# I隞乩寞曉唬皞 ip 敺, 靘憒 ip x.x.x.x, 臭誑 iptables 餅餅 P1 h4 s. m# Q' G% f& A+ v& f
撠 IP- iptables -A INPUT -p all -s x.x.x.x/32 -j DROP
銴鋆賭誨蝣 閫文 IP- iptables -D INPUT -p all -s x.x.x.x/32 -j DROP
銴鋆賭誨蝣 隞乩:
( h+ ?/ V- _) L- Q" n0 Chttps://www.phpini.com/linux/linux-netstat-detect-ddos
8 s1 \1 r8 ]3 s) rhttps://www.phpini.com/linux/count-ip-connections I. R9 v8 d: r/ {
https://www.phpini.com/linux/netstat-check-connections
( `% U9 H8 c: K9 t, j* z8 J=================================================
/ j f7 y; r9 ^3 {% ?' {1 h. E# ?. J血嚗' H8 p4 W; t6 h) O. S; v
亥岷芯port鋡怠芯函撘雿剁
$ d4 [0 h- H+ S5 B9 L1.)- netstat -tulpn | grep LISTEN
銴鋆賭誨蝣 2.)- lsof -i -P -n | grep LISTEN
銴鋆賭誨蝣 3.)- sudo nmap -sT -O localhost
銴鋆賭誨蝣 =================================================' |9 v6 h6 Y3 \0 w3 b- j( W" }
亥岷port雿函backlogbacklog閰脣憭改 嚗 https://cloud.tencent.com/developer/article/1644836
- |7 W& a z; o5 g: D( B5 m |
|