Re: ssh statistics ? connection slows down !

From: Steve Bonds (05gekfc02_at_sneakemail.com)
Date: 01/31/04

  • Next message: Darren Tucker: "Re: SSH and no-account logins"
    Date: Fri, 30 Jan 2004 16:05:47 -0800 (PST)
    To: secureshell@securityfocus.com
    
    

    On Tue, 27 Jan 2004, Lars Bohnsack lars.bohnsack-at-haeusler-net.biz
    |secureshell@securityfocus.com| wrote:

    > is it possible to have something like a real-time statistc about a ssh
    > connection?
    > Something like:
    > used bandwidth
    > throughput
    > start of the session
    > TX an RX of the session
    > roundtrip times or something like that

    Lars:

    Look at the generic TCP connection diagnostic utility "tcptrace". It will
    give you all these statistics for any captured TCP session.

    http://jarok.cs.ohiou.edu/software/tcptrace/tcptrace.html

    The only quirk is that it assumes than any connection that is idle for
    more than 2 minutes and then restarts is a new connection. If you see
    lots of "new" connections with the same source and destination
    address/port pairs in the report this is likely your problem. I have a
    patch to fix this "feature" if you need it.

    To use it, capture the TCP session using your favorite packet grabbing
    utility (e.g. tcpdump, ethereal, snoop, etc.) and run tcptrace with the
    appropriate options on that file.

      -- Steve


  • Next message: Darren Tucker: "Re: SSH and no-account logins"

    Relevant Pages

    • [Full-disclosure] Cisco PIX TCP Connection Prevention
      ... Cisco PIX TCP ... Connection Prevention, posted on November 22, 2005. ... By sending a TCP SYN packet with an incorrect checksum through a PIX ...
      (Full-Disclosure)
    • [Full-disclosure] Cisco PIX TCP Connection Prevention
      ... Cisco PIX TCP ... Connection Prevention, posted on November 22, 2005. ... By sending a TCP SYN packet with an incorrect checksum through a PIX ...
      (Full-Disclosure)
    • [NEWS] Cisco PIX TCP Connection DoS
      ... Get your security news from a reliable source. ... By crafting a special TCP packet and sending it to a vulnerable Cisco PIX, ... embryonic connection open until the embryonic connection timeout which is ...
      (Securiteam)
    • FreeBSD Security Advisory FreeBSD-SA-01:39.tcp-isn
      ... TCP network connections use an initial sequence number as part of the ... incoming connection is being established, ... Systems running insecure protocols which blindly trust a TCP ... requiring other authentication of the originator are vulnerable to ...
      (FreeBSD-Security)
    • Re: Firewall vs. IPS - Differences now (ISS, Intrushield 2.1?)
      ... If we expire a connection too early, ... The way we solved this at NFR is to never expire idle TCP states. ... For example the timeout for the SYN|ACK may have been ...
      (Focus-IDS)

  • Quantcast