Professional Documents
Culture Documents
alert tcp any any -> any any (msg: " TCP SYN packet flooding (simple or distributed)";
threshold: type both, track by_dst, count 10000, seconds 60; flow:stateless; flags:S,12;
sid:7; rev:1;)
#Initialize topology
Topo.__init__( self )
#PID
try:
return dpid
except IndexError:
#Add links
self.addLink('s1','s2',bw=100)
self.addLink('s1','s3',bw=100)
self.addLink('h1','s2',bw=100)
self.addLink('h2','s2',bw=100)
self.addLink('h3','s3',bw=100)
self.addLink('h4','s3',bw=100)
case "$1" in
-rule1s1)
rule1_s1=$2
shift
;;
-rule2s1)
rule2_s1=$2
shift
;;
*)
esac
shift
done
echo
"*********************************************************************
***"
sleep 10
echo
echo
"*********************************************************************
***"
4. Script Blokir
#!/bin/bash clear
logfile="/var/log/snort/alert.csv"
if [[ $src == *[:]* ]]
then
fi
if [[ $dst == *[:]* ]]
then
fi
echo
done
5. Data Hasil Pengujian Performansi
5.1. Delay Video Stream
TCP (Syn Flood )
25 Mbps 50 Mbps 75 Mbps 90 Mbps 91 Mbps 92 Mbps 93 Mbps 94 Mbps 95 Mbps 96 Mbps 97 Mbps 98 Mbps 99 Mbps 100 Mbps
Tanpa IPS 0.189 0.44 11.025 15.842 18.227 18.636 19.355 19.428 20.201 20.593 21.002 35.11 39.776 46.544
Terintegrasi IPS 0.441 0.872 140.334 170.019 173.150 175.968 178.523 180.886 184.015 186.114 189.005 190.524 196.531 197.170