[Oisf-users] Web aspirator detection

Peter Manev petermanev at gmail.com
Thu Nov 3 12:18:04 UTC 2011


Just out of curiosity - you don't want over N number of simultanious
connections from a particular IP ? correct?
If that is the case you could "firewall"-it.
Or you want just to detect the IP's?


On Thu, Nov 3, 2011 at 10:49 AM, Amrith Z <amrith at hotmail.fr> wrote:

>  Hi all,
> I'm looking for a way to detect web aspiration. I'm encountering a lot a
> simultaneous connexions from single IPs, which are scrawling all our web
> pages.
> Is there a way to detect aspiration, or to configure Suricata to alert
> when a single IP is having a lot of simultaneous connexions ?
> Thx!
> _______________________________________________
> Oisf-users mailing list
> Oisf-users at openinfosecfoundation.org
> http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users

Peter Manev
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20111103/afbe3f50/attachment-0002.html>

More information about the Oisf-users mailing list