I have a virtual server running Ubuntu 18.04 from a well known hosting company. This morning our Fortigate Firewall logs shows that my Win10 computer transferred 3.5TB to and 6.5TB from my virtual server over 13 hours (over last night) via SSH.
There are a couple of issues with this; First we know the figures quoted by the Fortigate Firewall are not correct, because a) the connection speed isn't fast enough able to do this over that time period, perhaps a 10th of the required speed, and b) the VPS logs show that it received 35GB and sent 65GB... many times less than the Fortigate reports. And secondly the only things that were open using SSH were Putty and WinSCP. Putty wasn't doing anything, and the bash history shows the only commands were related to starting and stopping Kestrel (dot net core server), it was doing nothing else. WinSCP wasn't doing anything either as far as I can tell. I'd moved a few folders around during the day.
Nothing came up with a virus scan on my local machine, there wasn't anything awry in the server logs, and the server has no third party packages other than the Microsoft .net core repos set up.
While the boss is OK that nothing sinister was going on I am not happy that something has ocurred that I can't even begin to answer.
I have a whole host of questions about this but right now I'll settle for:
- What could have caused this?
- Could it just have been an issue with the Fortigate as we know it's mis-reported the data transfer, or perhaps WinSCP in a loop?
- Has anyone ever had this happen to them at all?
Any clues gratefully received.