Welcome! Log In Create A New Profile

Advanced

Detect suspicious activity with nginx

Maxime Ducharme
August 09, 2011 05:18PM
Hi guys

We are looking for a way to detect suspicious activity on high-traffic
websites. Parsing log files is not good option here, our current nginx
config generates around 90G of logs for around 412K http requests each
days.

We are looking to use nginx to detect suspicious activity and generate
precise log when it happens for post-processing.

Some tools we are looking for would be something like

- Detect IPs which accessed /uri1/ X times without accessing other URI
in a period of time Y.

- Detect IPs that are indexing our site by accessing sequential uris
like /uri123, /uri124, /uri125, ...

We are using load balancing services (haproxy), we enabled realip module
in nginx, we need something that can work with it.

If you have any pointers / ideas / module names that could help us,
please let me know.

Have a good day

Max




_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Detect suspicious activity with nginx

Maxime Ducharme August 09, 2011 05:18PM

Re: Detect suspicious activity with nginx

ressaid August 09, 2011 08:50PM

Re: Detect suspicious activity with nginx

fbhosted August 09, 2011 08:56PM

Re: Detect suspicious activity with nginx

Calin Don August 12, 2011 07:40PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 297
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready