firewall |
ValdikSS , , IPv4-. "" , .. . :
: https-, http "" . . IPv4 , , , . , DoS- .
Looking Glass , - /32 , .. . : aka GIN aka Orange Business Services, Beeline, , , Obit , , ( ).
, IP-, " " LG: 1, 2, 3, 4, 5, 6. - , IPv4 IP, . ߠ, .
14 15:00 DNS- , pcap-, .
16 . .
abuse- netup.ru , URL, 2048 5 . AS DNS "" 8 , - "" , . Tele2 https "" dns, http, http proxy. Miralogic http. SPNet URL , "" . citytelecom , https , , "" , - .
| HTTPS | HTTP | Domain-only
asn | tiny | 2k/udp | 2k/tcp | tiny | 2k/udp | 2k/tcp | tiny | 2k/udp | 2k/tcp
------+------+--------+--------+------+--------+--------+------+--------+-------
50317 | 903 | 1416 | 1030 | 285 | 1295 | 1012 | 0 | 0 | 0
57835 | 207 | 0 | 0 | 200 | 0 | 0 | 200 | 0 | 0
38959 | 29 | 0 | 0 | 56 | 0 | 0 | 39 | 0 | 0
39475 | 155 | 217 | 217 | 0 | 0 | 0 | 151 | 209 | 209
42514 | 0 | 0 | 0 | 120 | 136 | 13 | 0 | 0 | 0
12668 | 0 | 0 | 0 | 95 | 103 | 18 | 0 | 0 | 0
43826 | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 33 | 12
56705 | 415 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0
16 gist, , ASN .
pcap- EDNS Client Subnet, 1%. , .. google ( "" ) DNS-, , DNS- . ⠗ , , EDNS Client Subnet: AS .
Client Subnet 4 , "" bit 0x20:
ts | src | query | client4
---------------------------+---------------+----------------------+--------------
2017-06-14 04:47:41.231796 | 187.1.128.119 | udp A zenitbET66.CoM | 200.248.248.0
2017-06-14 04:47:41.748585 | 187.1.128.119 | tcp A ZenItbET66.cOm | 200.248.248.0
2017-06-14 04:47:42.274296 | 187.1.128.119 | udp A zEnItbET66.coM | 200.248.248.0
2017-06-14 04:47:42.798544 | 187.1.128.119 | tcp A zeNitBET66.com | 200.248.248.0
0x20 5% 2.5% ( ASN).
EDNS EDNS UDP payload size, DNS-, . , EDNS 55% 4096 , .
2% , UDP- 512. irc.kristel.ru , "" , TCP. , 512 .
ts | proto | qtype | qname | udpsz
---------------------------+-------+-------+--------------------+------
2017-06-14 12:41:59.678401 | udp | A | zenitbet66.com | 512
2017-06-14 12:41:59.898596 | tcp | A | zenitbet66.com | 512
2017-06-14 12:42:32.14485 | udp | A | m.zenitbet66.com | 4096
2017-06-14 12:44:40.532815 | udp | A | www.kisa54.com | 4096
2017-06-14 12:56:54.083849 | udp | A | diplom-lipetsk.com | 4096
2017-06-14 12:56:54.311013 | tcp | A | diplom-lipetsk.com | 4096
2017-06-14 13:06:38.524876 | udp | A | www.cool-sino.com | 4096
, DNS amplification, .. 65527 , . , "" powerdns - resource records, truncated , TCP. powerdns DNS amplification UDP.
, DNS- TCP TCP Fast Open. , , , DNS , TCP.
10 looking glass /32 "" DNS IPv4 . , RIPE Atlas, , , , , 2049 A
:
, .. . , . :
sortlist
LUA - , RIPE Atlas 8844224, 8844225, 8844226, 8844227, 8844228, 8844229, 8844230, 8844231, 8844232, 8844233, 8844234, 8844235. 16 postgres:9.6. pcap- .