2
I have a windows server 2008 R2
which is victim of a DoS
attack. How can I find out which IP
is the source of attack?
I have a anti DoS
module on IIS 7.0
which works fine but it seems destination is not port 80 and the attack is blind (Attacker has attacked some IP addresses which are not mine) and just consumes my bandwidth. I have a 1000 Mbps network card which is fully utilized by attacker so he have at least a server with 1000 Mbps. I have unmetered bandwidth on this data center but security support is awful.
I have tried 'TCPView' to find more details but server freezes when the attack is started because of high CPU usage (100%).
Is there any software solution for this problem? how can I distinguish attacker IP address from normal users (connections with high transfer rate)?
Do you have some kind of firewall in the way (if so, what model?), or just the software firewall? Is it sitting out on the Internet, or NAT'ted? Do you need any other ports open other than 80? – KCotreau – 2011-08-02T13:29:54.987