Re: DDoS attack causing bad effect on conntrack searches

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Jesper Dangaard Brouer
Date: Thursday, April 22, 2010 - 1:38 pm

On Thu, 22 Apr 2010, Eric Dumazet wrote:


I think its plausable, there is a lot of modification going on.
Approx 40.000 deletes/sec and 40.000 inserts/sec.
The hash bucket size is 300032, and with 80000 modifications/sec, we are 
(potentially) changing 26.6% of the hash chains each second.

As can be seen from the graphs:
  http://people.netfilter.org/hawk/DDoS/2010-04-12__001/list.html

Notice that primarily CPU2 is doing the 40k deletes/sec, while CPU1 is 
caught searching...



Guess I have to reproduce the DoS attack in a testlab (I will first have 
time Tuesday).  So we can determine if its bad hashing or restart of the 
search loop.


The traffic pattern was fairly simple:

200 bytes UDP packets, comming from approx 60 source IPs, going to one 
destination IP.  The UDP destination port number was varied in the range 
of 1 to 6000.   The source UDP port was varied a bit more, some ranging 
from 32768 to 61000, and some from 1028 to 5000.


Cheers,
   Jesper Brouer

--
-------------------------------------------------------------------
MSc. Master of Computer Science
Dept. of Computer Science, University of Copenhagen
Author of http://www.adsl-optimizer.dk
-------------------------------------------------------------------
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Thu Apr 22, 5:58 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Thu Apr 22, 6:17 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Thu Apr 22, 6:31 am)
Re: DDoS attack causing bad effect on conntrack searches, Paul E. McKenney, (Thu Apr 22, 8:51 am)
Re: DDoS attack causing bad effect on conntrack searches, Paul E. McKenney, (Thu Apr 22, 9:34 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Thu Apr 22, 1:38 pm)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Thu Apr 22, 2:28 pm)
Re: DDoS attack causing bad effect on conntrack searches, Eric Dumazet, (Thu Apr 22, 10:44 pm)
Re: DDoS attack causing bad effect on conntrack searches, Jan Engelhardt, (Fri Apr 23, 12:23 am)
Re: DDoS attack causing bad effect on conntrack searches, Eric Dumazet, (Fri Apr 23, 12:46 am)
Re: DDoS attack causing bad effect on conntrack searches, Jan Engelhardt, (Fri Apr 23, 12:55 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Fri Apr 23, 1:40 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 3:35 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 3:36 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 3:55 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 3:56 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 4:06 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Fri Apr 23, 5:45 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Fri Apr 23, 6:57 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Sat Apr 24, 4:11 am)
Re: DDoS attack causing bad effect on conntrack searches, Jesper Dangaard Brouer, (Mon Apr 26, 7:36 am)
Re: DDoS attack causing bad effect on conntrack searches, Eric Dumazet, (Mon May 31, 10:05 pm)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Tue Jun 1, 3:18 am)
Re: DDoS attack causing bad effect on conntrack searches, Patrick McHardy, (Tue Jun 1, 3:41 am)
[PATCH nf-next-2.6] conntrack: IPS_UNTRACKED bit, Eric Dumazet, (Fri Jun 4, 9:25 am)
[PATCH nf-next-2.6 2/2] conntrack: per_cpu untracking, Eric Dumazet, (Fri Jun 4, 1:15 pm)
Re: [PATCH nf-next-2.6] conntrack: IPS_UNTRACKED bit, Patrick McHardy, (Tue Jun 8, 7:12 am)
Re: [PATCH nf-next-2.6 2/2] conntrack: per_cpu untracking, Patrick McHardy, (Tue Jun 8, 7:29 am)
Re: [PATCH nf-next-2.6 2/2] conntrack: per_cpu untracking, Patrick McHardy, (Wed Jun 9, 5:45 am)