You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian Linux开机自启脚本开发:每10秒统计每秒入站数据包数

Hey there! Let's walk through this step by step—since you're new to Linux scripting, I'll break down everything you need to build your packet-monitoring script and set it to run automatically on Debian boot. Perfect for your DoS mitigation research!

1. Build the Packet-Counting Script

We'll use the ip command (part of Debian's default iproute2 toolset) to track inbound packet counts, since it's reliable and doesn't require extra installs. Create a script file (e.g., /usr/local/bin/packet-monitor.sh) with this content:

#!/bin/bash
# Replace with your actual network interface (run `ip link` to find it, e.g., eth0, enp0s3)
INTERFACE="eth0"

# Initialize the first inbound packet count
prev_rx=$(ip -s link show "$INTERFACE" | grep -A 1 RX | tail -n 1 | awk '{print $1}')

# Loop to count packets every second, and output a summary every 10 seconds
count=0
total_packets=0
while true; do
    sleep 1
    # Get current inbound packet count
    curr_rx=$(ip -s link show "$INTERFACE" | grep -A 1 RX | tail -n 1 | awk '{print $1}')
    # Calculate packets received in the last second
    packets_per_sec=$((curr_rx - prev_rx))
    # Update the previous count for the next iteration
    prev_rx=$curr_rx

    # Track totals for the 10-second window
    count=$((count + 1))
    total_packets=$((total_packets + packets_per_sec))

    # Every 10 seconds, print the summary
    if [ $count -eq 10 ]; then
        avg_packets=$((total_packets / count))
        echo "$(date '+%Y-%m-%d %H:%M:%S') - Average inbound packets/sec over last 10s: $avg_packets | Last second: $packets_per_sec"
        # Reset counters for the next window
        count=0
        total_packets=0
    fi
done

What this script does:

  • Tracks your specified network interface's inbound packet count
  • Calculates how many packets arrive each second
  • Every 10 seconds, it outputs the average packets per second over that window, plus the count from the most recent second
  • Logs timestamps so you can correlate traffic spikes with potential DoS attempts
2. Make the Script Executable

Run this command to give the script permission to run:

sudo chmod +x /usr/local/bin/packet-monitor.sh

Debian uses systemd by default, so this is the most reliable way to ensure your script starts automatically and restarts if it crashes.

  1. Create a systemd service file:
    sudo nano /etc/systemd/system/packet-monitor.service
    
  2. Paste this content into the file:
    [Unit]
    Description=Inbound Packet Monitor for DoS Research
    After=network.target  # Wait until the network is up before starting
    
    [Service]
    ExecStart=/usr/local/bin/packet-monitor.sh
    Restart=always  # Restart the script if it stops unexpectedly
    User=root  # Required to access network interface statistics
    StandardOutput=append:/var/log/packet-monitor.log  # Save output to a log file
    StandardError=append:/var/log/packet-monitor.log  # Save errors to the same log
    
    [Install]
    WantedBy=multi-user.target  # Start when the system reaches multi-user mode
    
  3. Save and exit the editor (Ctrl+O, Enter, then Ctrl+X in nano).
  4. Reload systemd to recognize the new service:
    sudo systemctl daemon-reload
    
  5. Enable the service to run on boot:
    sudo systemctl enable packet-monitor.service
    
  6. Start the service immediately to test it:
    sudo systemctl start packet-monitor.service
    
4. Verify It's Working

Check the log file after 10 seconds to see if data is being recorded:

tail /var/log/packet-monitor.log

You should see lines like this:

2024-05-20 14:30:00 - Average inbound packets/sec over last 10s: 12 | Last second: 15

To test, you can send traffic to your machine (e.g., ping from another device) and watch the counts increase.

Bonus: Troubleshooting Tips
  • If you don't see data, double-check your network interface name (run ip link to list all interfaces).
  • Ensure the script has root permissions—network stats require elevated access.
  • If you want to track specific protocols (e.g., TCP, UDP) or ports later, you can modify the script to use tcpdump instead of ip (e.g., tcpdump -i $INTERFACE -c 0 -n tcp | wc -l), but start with the basic version first.

内容的提问来源于stack exchange,提问作者Aidan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:53:15