Monitoring a SYN Attack - Verbose Output
This example shows the verbose output.
> sim synatk monitor –v
+-----------------------------------------------------------------------------+
| SYN Defender statistics |
+-----------------------------------------------------------------------------+
| Status Under Attack (!) |
| Spoofed SYN/sec 534000 |
+-----------------------------------------------------------------------------+
| IF | Topology | Defend (sec) | SYN cookie rate |
| | | | Sent | BAU (cps) | Spoofed |
+-----------------------------------------------------------------------------+
| eth2-01 | External | 28 | 345345 | 40 | 95 % |
| eth2-02 | External | 12 | 150 | 50 | 33 % |
+-----------------------------------------------------------------------------+
| Sum | 345495 | 90 | 93 % |
+-----------------------------------------------------------------------------+
Output Description
Column
|
Description
|
IF
|
The interface name
|
Topology
|
The interface topology as defined in SmartDashboard.
|
Defend
|
The attack duration in seconds.
|
Sent SYN cookie rate
|
Number of SYN packets received per second.
|
BAU
|
Business as usual. The number of legitimate connections handled per second.
|
Spoofed
|
The percentage of spoofed SYN packets out of all traffic.
|
|