feat: DDoS detector for ports 80/443 with Telegram alert (cron 1min, ss-based)
This commit is contained in:
58
README.md
Normal file
58
README.md
Normal file
@@ -0,0 +1,58 @@
|
||||
# DDoS Detector (port 80/443 → Telegram alert)
|
||||
|
||||
Script Python ringan yang monitor koneksi aktif ke **port 80 & 443** tiap 1 menit.
|
||||
Kalau ada IP yang bomb (> batas) atau total koneksi port melebihi batas, kirim **alert ke Telegram**.
|
||||
Pakai `ss` (bawaan Linux), gak butuh dependency pip.
|
||||
|
||||
## Cara kerja
|
||||
|
||||
1. Cron jalanin `ddos_detector.py` tiap 1 menit
|
||||
2. Hitung koneksi per-IP ke port 80 & 443 (`ss -tn src :80 or src :443`)
|
||||
3. Kalau `koneksi 1 IP > CONN_PER_IP` atau `total port > CONN_TOTAL` → alert Telegram
|
||||
4. State file cegah spam: cuma alert pas **crossing threshold**, + kirim "cleared" kalau balik normal
|
||||
|
||||
## Config
|
||||
|
||||
Semua via env (atau file `/root/stock-monitor/.env`):
|
||||
|
||||
| Var | Default | Keterangan |
|
||||
|-----|---------|-----------|
|
||||
| `TELEGRAM_BOT_TOKEN` | (dari .env) | token bot |
|
||||
| `TELEGRAM_CHAT_ID` | `5722352727` | chat tujuan |
|
||||
| `DDOS_PER_IP` | `100` | batas koneksi per IP per port |
|
||||
| `DDOS_TOTAL` | `500` | batas total koneksi per port |
|
||||
|
||||
## Install
|
||||
|
||||
```bash
|
||||
# taruh script
|
||||
cp ddos_detector.py /root/ddos_detector.py
|
||||
|
||||
# pastikan python3 + ss ada
|
||||
which python3 ss
|
||||
|
||||
# crontab tiap 1 menit
|
||||
(crontab -l 2>/dev/null; echo "* * * * * /usr/bin/python3 /root/ddos_detector.py >> /root/ddos_detector.log 2>&1") | crontab -
|
||||
```
|
||||
|
||||
## Output
|
||||
|
||||
- Log: `/root/ddos_detector.log` (stats tiap menit, gak ada secret)
|
||||
- State: `/root/ddos_state.json` (flag alerting, cegah spam)
|
||||
- Telegram:
|
||||
- `🚨 DDoS ALERT @ ...` + top IP kalau anomali
|
||||
- `✅ DDoS alert cleared @ ...` kalau balik normal
|
||||
|
||||
## Test manual
|
||||
|
||||
```bash
|
||||
python3 /root/ddos_detector.py
|
||||
# lihat log
|
||||
tail -f /root/ddos_detector.log
|
||||
```
|
||||
|
||||
## Catatan
|
||||
|
||||
- Hanya monitor 80/443 (permukaan publik). Kalau mau port lain, edit `PORTS` di script.
|
||||
- Threshold default konservatif — turunin `DDOS_PER_IP` (misal 50) kalau mau lebih sensitif.
|
||||
- Gak auto-mitigasi (cuma alert). Buat mitigasi: iptables rate-limit / Cloudflare "Under Attack".
|
||||
Reference in New Issue
Block a user