/
usr
/
share
/
doc
/
bpfcc-tools
/
examples
/
tracing
/
/usr/share/doc/bpfcc-tools/examples/tracing
mkdir
upload
Name
Size
Mode
Actions
biolatpcts.py
3312
0755
edit
dl
rm
biolatpcts_example.txt
650
0644
edit
dl
rm
bitehist.py
1397
0755
edit
dl
rm
bitehist_example.txt
1208
0644
edit
dl
rm
CMakeLists.txt
276
0644
edit
dl
rm
dddos.py
3818
0755
edit
dl
rm
dddos_example.txt
2112
0644
edit
dl
rm
disksnoop.py
1947
0755
edit
dl
rm
disksnoop_example.txt
1587
0644
edit
dl
rm
hello_fields.py
679
0755
edit
dl
rm
hello_perf_output.py
1270
0755
edit
dl
rm
hello_perf_output_using_ns.py
1843
0755
edit
dl
rm
kvm_hypercall.py
1520
0755
edit
dl
rm
kvm_hypercall.txt
1782
0644
edit
dl
rm
mallocstacks.py
1942
0755
edit
dl
rm
mysqld_query.py
1701
0755
edit
dl
rm
mysqld_query_example.txt
499
0644
edit
dl
rm
nflatency.py
6214
0755
edit
dl
rm
nodejs_http_server.py
1376
0755
edit
dl
rm
nodejs_http_server_example.txt
276
0644
edit
dl
rm
stacksnoop.py
3252
0755
edit
dl
rm
stacksnoop_example.txt
2871
0644
edit
dl
rm
stack_buildid_example.py
3106
0755
edit
dl
rm
strlen_count.py
1331
0755
edit
dl
rm
strlen_hist.py
1856
0755
edit
dl
rm
strlen_hist_ifunc.py
3800
0755
edit
dl
rm
strlen_snoop.py
1384
0755
edit
dl
rm
sync_timing.py
1390
0755
edit
dl
rm
task_switch.c
499
0644
edit
dl
rm
task_switch.py
486
0755
edit
dl
rm
tcpv4connect.py
2413
0755
edit
dl
rm
tcpv4connect_example.txt
1063
0644
edit
dl
rm
trace_fields.py
589
0755
edit
dl
rm
trace_perf_output.py
1600
0755
edit
dl
rm
undump.py
3602
0755
edit
dl
rm
undump_example.txt
886
0644
edit
dl
rm
urandomread-explicit.py
1511
0755
edit
dl
rm
urandomread.py
1032
0755
edit
dl
rm
urandomread_example.txt
675
0644
edit
dl
rm
vfsreadlat.c
896
0644
edit
dl
rm
vfsreadlat.py
1336
0755
edit
dl
rm
vfsreadlat_example.txt
3619
0644
edit
dl
rm
Edit:
/usr/share/doc/bpfcc-tools/examples/tracing/dddos_example.txt
(2112B)
Demonstrations of dddos.py, the Linux eBPF/bcc version. This tracks ip_rcv function (using kprobe) and elapsed time between received packets to detect potential DDOS attacks. The following steps illustrates the usage of dddos : 1 - Start dddos.py : # ./dddos.py DDOS detector started ... Hit Ctrl-C to end! TIME(s) MESSAGE 2 - Launch hping3 (or any other flooder) in another terminal as shown below: # hping3 localhost -S -A -V -p 443 -i u100 3 - dddos.py triggers alerts and reports a DDOS attack: DDOS detector started ... Hit Ctrl-C to end! TIME(s) MESSAGE 2019-01-16 11:55:12.600734 DDOS Attack => nb of packets up to now : 1001 2019-01-16 11:55:12.600845 DDOS Attack => nb of packets up to now : 1002 2019-01-16 11:55:12.600887 DDOS Attack => nb of packets up to now : 1003 2019-01-16 11:55:12.600971 DDOS Attack => nb of packets up to now : 1004 2019-01-16 11:55:12.601009 DDOS Attack => nb of packets up to now : 1005 2019-01-16 11:55:12.601062 DDOS Attack => nb of packets up to now : 1006 2019-01-16 11:55:12.601096 DDOS Attack => nb of packets up to now : 1007 2019-01-16 11:55:12.601195 DDOS Attack => nb of packets up to now : 1008 2019-01-16 11:55:12.601228 DDOS Attack => nb of packets up to now : 1009 2019-01-16 11:55:12.601331 DDOS Attack => nb of packets up to now : 1010 2019-01-16 11:55:12.601364 DDOS Attack => nb of packets up to now : 1011 2019-01-16 11:55:12.601470 DDOS Attack => nb of packets up to now : 1012 2019-01-16 11:55:12.601505 DDOS Attack => nb of packets up to now : 1013 2019-01-16 11:55:12.601621 DDOS Attack => nb of packets up to now : 1014 2019-01-16 11:55:12.601656 DDOS Attack => nb of packets up to now : 1015 2019-01-16 11:55:12.601757 DDOS Attack => nb of packets up to now : 1016 2019-01-16 11:55:12.601790 DDOS Attack => nb of packets up to now : 1017 2019-01-16 11:55:12.601892 DDOS Attack => nb of packets up to now : 1018 2019-01-16 11:55:12.601925 DDOS Attack => nb of packets up to now : 1019 2019-01-16 11:55:12.602028 DDOS Attack => nb of packets up to now : 1020 Remark : Use Ctrl-C to stop dddos.py
Save
cmd:
run