现在我们攻击的网站服务器被大量来历不明的肉鸡攻击,来自全国不同Ip的服务器对我们公司的服务器发起大量的HTTP请求,结果导致正常的用户访问不了了。
这个问题应该怎么解决?
下面是记录到的部分信息:
39.68.37.61 - - [16/Sep/2014:17:53:38 +0800] "GET / HTTP/1.0" 403 280 "w4mvtbpnpj.com" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.2 (KHTML, like Gecko) Chrome/4.0.221.7 Safari/532.2"
60.189.226.158 - - [16/Sep/2014:17:53:38 +0800] "GET / HTTP/1.0" 403 280 "unm5s6tn6e.org" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
180.175.213.227 - - [16/Sep/2014:17:53:38 +0800] "GET / HTTP/1.0" 403 280 "y8j9beo4db.de" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
49.88.39.116 - - [16/Sep/2014:17:53:24 +0800] "POST / HTTP/1.0" 403 280 "2hf5eeme0v.de" "Mozilla/5.0 (iPhone; CPU iPhone OS 5_1_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9B206 Safari/7534.48.3"
27.196.97.94 - - [16/Sep/2014:17:53:31 +0800] "POST / HTTP/1.0" 403 280 "zjowle45fr.de" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
112.102.121.173 - - [16/Sep/2014:17:53:39 +0800] "GET / HTTP/1.0" 403 280 "uuhuqm4wuj.me" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
223.64.63.146 - - [16/Sep/2014:17:53:39 +0800] "GET / HTTP/1.0" 403 280 "0s5lws63qo.me" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
222.76.194.218 - - [16/Sep/2014:17:53:15 +0800] "POST / HTTP/1.0" 403 280 "mfs8kxm1bj.de" "Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3"
112.92.75.146 - - [16/Sep/2014:17:53:39 +0800] "GET / HTTP/1.0" 403 280 "3mceargcwy.de" "Mozilla/4.0 (Windows; U; Windows NT 5.1; zh-TW; rv:1.9.0.11)"
221.219.109.59 - - [16/Sep/2014:17:53:39 +0800] "GET / HTTP/1.0" 403 280 "rh51qxllon.org" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.46 Safari/536.5"
以前从未遇到这种事,不知道怎么解决?
目前就是100兆带宽全部占满,结果正常用户访问时没有响应了?得很长时间打开主页?这个有什么很好的解决方案?需不需要提供网络服务提供商来解决?是不是在我们的服务器上屏蔽这些恶意IP就可以了?带宽问题能不能仅通过屏蔽IP就能搞定?
我也知道升级到千兆网卡能够解决这个问题,但是目前我们希望话最小的成本最快的速度解决这个问题?
请分析一下解决方案。跪求。
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课