Web服务器可用性与完整性监控:开源工具推荐及检测维度建议
Hey Lynow, great question—monitoring web server availability and integrity is such a critical part of keeping your services safe and reliable, and combining open-source tools with custom Python code is a smart approach. Let’s break this down into actionable steps and tool recommendations:
一、可用性监控:简单但关键的基础检测
You’re right that checking HTTP 200 status codes and response times is the core here. Here’s how to level this up:
- Python 实现快速检测: Use the
requestslibrary for straightforward HTTP checks. A quick snippet to get you started:import requests from datetime import datetime def check_availability(url): try: start_time = datetime.now() response = requests.get(url, timeout=10) response_time = (datetime.now() - start_time).total_seconds() if response.status_code == 200: print(f"✅ {url} is UP | Response time: {response_time:.2f}s") else: print(f"❌ {url} returned status code {response.status_code}") except requests.exceptions.RequestException as e: print(f"❌ {url} is DOWN | Error: {str(e)}") - 开源可视化工具: For long-term monitoring with alerts, tools like Uptime Kuma let you track multiple servers, set uptime thresholds, and get notifications (Slack, email, etc.). If you want more granular metrics (like CPU/memory alongside availability), Prometheus + Grafana is a powerful combo—you can write custom exporters in Python to feed data into it.
二、完整性监控:深入检测防篡改与攻击
This is trickier, but there are solid open-source tools and Python workflows to cover your proposed checks:
1. 文件哈希对比与恶意文件检测
- Local hash checks: Use Python’s built-in
hashlibto generate MD5/SHA256 hashes of critical files (like web root assets, configs) and store them securely. Run periodic scripts to re-calculate hashes and flag mismatches. - Malware scanning: ClamAV is a free open-source antivirus tool you can integrate with Python (via
pyclamdlibrary) to scan files for known threats. While VirusTotal is useful, relying solely on it isn’t ideal for privacy or offline checks—ClamAV gives you local control.
2. 网页篡改(Defacing)检测
- Custom hash checks: Extend your Python script to pull the full HTML of key pages, generate hashes, and compare against a baseline. If the hash changes unexpectedly, trigger an alert.
- Specialized tools: Wazuh is an open-source SIEM/EDR tool that includes file integrity monitoring (FIM)—it can automatically track changes to web files and alert you on unauthorized modifications. Tools like OpenVAS also include web page integrity scanning as part of their vulnerability assessment suite. URLSCAN is another option for checking public-facing page changes, but you can pair it with periodic scraping to validate locally.
3. 新增页面检测
- Use a Python crawler like
Scrapyto periodically crawl your entire site and generate a list of URLs. Compare this list against a baseline—any new URLs that aren’t part of your expected deployments should be flagged for review. - Alternatively, monitor your web server access logs for requests to unexpected paths (tools like ELK Stack or Fluentd can help parse and analyze logs at scale).
4. 源码安全检查
- For server-side code (like Python apps), use Bandit—an open-source static code analyzer that flags common security issues (hardcoded secrets, insecure function calls).
- If you’re running PHP or other languages, tools like PHPStan (for PHP) or ESLint (with security plugins for JS) can help catch vulnerable code patterns.
三、额外的检测维度建议
Beyond what you’ve listed, here are a few more checks to strengthen your monitoring:
- 异常请求监控: Track unusual traffic patterns—like sudden spikes in 404 errors, repeated requests from single IPs, or weird User-Agent strings. Tools like Fail2ban can automatically block malicious IPs based on log patterns.
- 端口与服务监控: Use Nmap (or Python’s
python-nmaplibrary) to periodically scan your server’s open ports—unexpected open ports could indicate a breach. - 进程与资源监控: Use
psutilin Python to track running processes, CPU, and memory usage. Sudden spikes or unknown processes are red flags.
工具汇总
Python Libraries
requests: HTTP availability checkshashlib: Local file hash generationscrapy: Site crawling for URL comparisonpsutil: System resource/process monitoringbandit: Static code security analysispyclamd: Integrate with ClamAV for malware scanning
Open-Source Tools
- Uptime Kuma: Simple uptime monitoring with alerts
- Prometheus + Grafana: Advanced metrics monitoring and visualization
- Wazuh: File integrity monitoring and SIEM
- OpenVAS: Vulnerability and integrity scanning
- ClamAV: Local malware detection
- Fail2ban: Brute-force attack mitigation
Combining these tools with your custom Python scripts should give you a robust monitoring setup. If you have specific edge cases (like static vs. dynamic sites), feel free to refine these workflows further!
备注:内容来源于stack exchange,提问作者Lynow

