What do DoS/ DDoS TCP SYN Floods and Layer 7/HTTP floods look like on a firewall log?

I am looking for some examples of log files for DoS or DDoS attacks that show a SYN Flood or a HTTP/Layer 7 Flood. I have had a google, but can’t seem to find anything.

Would the incoming packet sizes differ between a SYN Fl… Continue reading What do DoS/ DDoS TCP SYN Floods and Layer 7/HTTP floods look like on a firewall log?

DNS flood vs DNS Amplification attack: How is one considered a network/transport layer attack and the other a application layer attack?

I am reading a survey on DDoS attacks and they describe how these attacks can be classified by either Network/Transport level attacks and Application level attacks. In their examples, they classify DNS flooding as network/tra… Continue reading DNS flood vs DNS Amplification attack: How is one considered a network/transport layer attack and the other a application layer attack?

UDP flood 300 Kbps + SYN probes / other attacks. Flood or DDoS at low rate?

So for over 2 weeks, Im receiving what appears a combination of attacks non-stop 24/7.

First this UDP flood at a strangely small rate of 280 Kbps / 110 pps (360 bytes length)

02:29:41.978484 IP (tos 0x0, ttl 48, id 56020, offset 0, flags… Continue reading UDP flood 300 Kbps + SYN probes / other attacks. Flood or DDoS at low rate?