DDoS Detection

sozie

Member
Apr 5, 2020
33
3
13
32
Paris, France
shiftek.fr
Hello everyone,

My question may seem a little silly to you, but I think it's important. During the marketing of containers (so VPS eh), it regularly happens that people make outbound DDoS attacks.

My question being, is it possible to set up a script, or any other solution on Proxmox, that would allow this detection, and would suspend the service concerned.

Thank you in advance.
 
hi,

if the attacks are outbound from your hosts, then your best bet to monitor such activity would be checking the logs in your firewall. depending on your firewall it might have IDS-like capabilities. otherwise you could try setting up any network monitoring solution to look for high amounts of outbound traffic.
 
Hello,

Thank you for your response. The problem being that attacks coming from our hosts can be very important because of the network, and can impact during a strong attack (everything depends on the offer of the person, and therefore the bandwidth allocated to him) our network globally.

That's why I wanted to see with you, if you know of a monitoring system that has already been created, and that I could set up? Thank you in advance.
 
Thank you for your response. It does sound interesting. The question being, is it well managed with Proxmox? What I mean is, is it going to analyze only local traffic, or all VM/CT?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!