当前位置:网站首页>The performance and viewing methods of websites attacked by DDoS
The performance and viewing methods of websites attacked by DDoS
2022-07-29 06:35:00 【Zhongyun era - defense testable - Xiaoyu】
With the simplification of network attack , Now DDoS attack It has not only appeared in large websites , Even a lot of small and medium-sized websites and even personal websites may be faced with being DDoS The risk of attack . Maybe a lot of webmasters are right DDoS Attacks don't know much about , When a website is attacked in time, it can't be found in time , Causes the website to appear frequently big cannot open the situation ,, In order to let stationmaster people avoid network to receive DDoS The impact on the attack . Let's introduce the website in detail DDoS The performance of the attack and how to view it .
The website was DDoS The performance of the
1. The server CPU Be heavily occupied
DDoS The attack is actually a malicious resource occupation attack , The attacker sends a large number of invalid requests to the target server by using broiler or attack software , Causes the server's resources to be occupied by a large number of , So the normal process is not handled effectively , In this way, the website will open slowly . If the server can pop up for a certain period of time CPU High occupancy , Then it may be that the website has been CC The impact of the attack .
2. Bandwidth is heavily used
Taking up bandwidth resources is usually DDoS One of the main means of attack , After all, for many small businesses or personal websites , Bandwidth resources can be said to be very limited , When the bandwidth of the network is occupied by a large number of invalid data , Normal traffic data requests are very difficult to be processed by the server . If the uplink bandwidth utilization rate of the server reaches 90% When above , Then your website usually appears to be DDoS The possibility of attack .
3 The server is not connected to , The website can't be opened
If the web server is massive DDoS When the attack , It may cause server blue screen or crash , This means that the server is no longer connected , There is a connection error on the website . Of course, when this kind of request occurs, we'd better confirm whether the server is caused by hardware failure and so on , Otherwise, we should do a good job in the defense of the first segment when connecting to the server .
4. domain name ping Don't out IP
Perhaps the stationmaster of this kind of circumstance may compare little consider , This is also true DDoS A manifestation of attack , Just attack the target of the attack is the website DNS Domain name server . In the event of such an attack ,ping Server's IP It's connected normally , But the website just can't be opened normally , And in ping The domain name will appear abnormal ping General information .
In fact, in life ,DNS It is very common for domain name servers to be attacked , For example, when we have network access , Found that all websites can not be opened normally , however QQ The network application can still run normally .
because DDoS There are many types of attacks , It's hard to judge the type of network attack simply by the performance of the website , So we can start from the server side , Use common commands to make judgments :
The first type :CC Class attack
command :netstat –na,
If a large number of ESTABLISHED Connection state of Single IP Up to dozens or even hundreds
The second type :SYN Class attack
command ::netstat –an,
If a large number of SYN_RECEIVED Connection state of
The third type :UDP Class attack
Observe the status of the network card Accept a large number of packets per second
Network state :netstat –nan TCP The message is OK
The fourth type :TCP Flood attack
command :netstat –an,
If a large number of ESTABLISHED Connection state of Single IP Up to dozens or even hundreds
The above is the website by DDoS The performance of the attack and the related introduction of the viewing method , For website operation ,DDoS It's a huge impact , Even if there are regular DDoS When the attack , May also be destructive to the site , Therefore, the stationmaster should guard against DDoS Need more attention , Once the site appears to receive DDoS The performance of the attack , Take the necessary defensive measures immediately .
边栏推荐
- 虹科分享 | 测试与验证复杂的FPGA设计(2)——如何在IP核中执行面向全局的仿真
- Thinking about MySQL taking shell through OS shell
- 七、 下一代互联网IPV6
- UDP套接口通信实验
- 虹科案例 | PAC:一种整合了softPLC控制逻辑、HMI和其他服务功能的集成控制解决方案
- Solution for website being suspended
- c语言面试准备一(谈谈理解系类)
- Design and simulation code of 4-bit subtracter based on FPGA
- day09_static&final&代码块&抽象类&接口&内部类
- Official tutorial redshift 07 instances and proxy
猜你喜欢
随机推荐
文件系统一
day15_ generic paradigm
HOG+SVM实现行人检测
day03_2_作业
多线程服务器编程
Official tutorial redshift 09 camera
Leetcode - Tips
c语言面试准备一(谈谈理解系类)
Plugin location in mavan
FPGA - odd even frequency division and decimal frequency division code routine
虹科为您分享EtherCAT demo,教您如何从其他协议快速过渡到EtherCAT工业总线
虹科方案 | 在数字化的变电站中低成本实现无缝集成的独特解决方案
day13_ Under multithreading
PDO的使用
虹科分享 | 带你全面了解“CAN总线错误”(四)——在实践中生产和记录CAN错误
详解FIR滤波器和IIR滤波器的区别
虹科分享 | 带您全面认识“CAN总线错误”(一)——CAN总线错误与错误帧
Official tutorial redshift 08 light
五、 无线通信网
超低成本DDoS攻击来袭,看WAF如何绝地防护








