Published on: September 10, 2014 by Geo Paul

Apache: identify number of connections from a specific IP


Some times the webserver become loaded heavily due to large no. of inbound connections and makes the server sluggish or non-responsive. This is quite evident during DOS or DDOS attacks.In DDOS attack detection you can use the following script to identify the IP and the no. of connections active on a server using the following commands

netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n


netstat -plan | grep :80 | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n

The output would look like the following


The first column represents the no. of connections while the second column represents the source IP


