427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet279/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   275   276   277   278   279   280   281   282   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
342
Chapter 9 • Advanced Ourmon Techniques
427_Botnet_09.qxd 1/8/07 4:45 PM Page 342


Q: 
Is Linux or FreeBSD better for a probe? 
A: 
This is a good question.There are some tradeoffs here. For example, with
Linux there are more people working on more network device drivers or
supporting them than for FreeBSD. On the other hand, the basic sub-
system for getting packets out of the kernel is better with FreeBSD than
with Linux. (We have measured this in our lab at PSU with a high-speed
packet generator.) Phil Wood at http://public.lanl.gov/cpw has a libpcap
variation for Linux that pairs libpcap changes with the Linux kernel sup-
plied memory-mapped ring buffer for packet sniffing, and this system
(libpcap+kernel) substantially improves Linux performance. We use
FreeBSD with Intel NICs and insist on at least a dual-core CPU. At this
time, we recommend FreeBSD.
Q: 
Besides interrupts, are there other possible sources of packet loss? 
A: 
Packet loss during a DDoS attack is a difficult problem with multiple
facets. We have discovered that some NICs might simply lose packets if
too many small packets are arriving at the port. On both BSD and Linux,
the 
netstat –in
command might show possible input errors and should be
used to check your NIC to see if it has large amounts of errors.
Unfortunately, we can’t recommend anything useful here other than to try
another kind of NIC.
www.syngress.com
Advanced Ourmon Techniques • Chapter 9
343
Frequently Asked Questions
The following Frequently Asked Questions, answered by the authors of this
book, are designed to both measure your understanding of the concepts pre-
sented in this chapter and to assist you with real-life implementation of these
concepts. To have your questions about this chapter answered by the author,
browse to 

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   275   276   277   278   279   280   281   282   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish