[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

I've noticed odd attack behavior when setting DirCache 0 in the middle
of an attack. As mentioned previously, doing that causes the attack to
switch from causing massive outbound traffic to massive inbound traffic,
although with less effect on CPU load. But this attack has some unique
patterns: It alternates between a "pulsing" phase that lasts 15+ minutes
and a "steady" phase that lasts about 3 minutes. When pulsing, traffic
comes in bursts every 3-5 seconds at over 1 Gbps peak. When steady, it
seems to be causing the relay to receive 400-600 Mbps.

I wonder if the "steady" phase is trying to measure the effect of the
"pulsing" phase or something.

No idea if this also happens when DirCache 1 however.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCarMTOAAKCRAw+TRLM+X4
xgk1AP9TJLaJfeG745mpSmr8/6ru0/Paks1gp2DNrEFEjVh26gEArcE7G3EIESmv
b4Ia9CUpXZMAn9ZRQSx3LRFrA57Wogk=
=EI4H
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx