Security Basics mailing list archives

Any good method to check network overload?


From: swin <swin () student dlut edu cn>
Date: Mon, 3 Mar 2003 15:55:44 +0800

Hello!

        I am doing researtch on protecting system from DDoS attacking,in 
my researth work ,there is a part is to find network is overload and
raise alarm .
        Here ,network overload means in certain  time ,network is very 
busy ,servers or network equipment can not deal with so much request 
and make the entire network system very slow. As known ,when systems
are in DDoS attacking ,it can cause this situation,but also when sometimes a lot of normal user are using the server 
together ,it also
approach this situation.
        Right now, I do not care about what really cause this network 
overload, alse if I am energetic enough I can take care of the 
system 24 hours a day, but I want to use a program automatically check this situation,when our system is in overload,it 
can alarm.
        Before this I also thought some methods to check ,for example I 
used to try to calculate the average load of the system and use this
value multiply certain coefficient as the systen's max load when 
exceed this so call max load we consider it overload,but this method
I'm not satisfied .
        The second achive is to check server or network equipment's 
network stack queue,if the queue is too long ,it represents the system
are too busy to deal with so much request,but I'm also not sure about
this method ,so I want know other's opinion.
        Alse if any others have better way to check this overload ,I'm so
glad to hear it !
        Thanks in advance!
     
        Swin. wang 

Current thread: