Debian Linux开机自启脚本开发:每10秒统计每秒入站数据包数
Hey there! Let's walk through this step by step—since you're new to Linux scripting, I'll break down everything you need to build your packet-monitoring script and set it to run automatically on Debian boot. Perfect for your DoS mitigation research!
We'll use the ip command (part of Debian's default iproute2 toolset) to track inbound packet counts, since it's reliable and doesn't require extra installs. Create a script file (e.g., /usr/local/bin/packet-monitor.sh) with this content:
#!/bin/bash # Replace with your actual network interface (run `ip link` to find it, e.g., eth0, enp0s3) INTERFACE="eth0" # Initialize the first inbound packet count prev_rx=$(ip -s link show "$INTERFACE" | grep -A 1 RX | tail -n 1 | awk '{print $1}') # Loop to count packets every second, and output a summary every 10 seconds count=0 total_packets=0 while true; do sleep 1 # Get current inbound packet count curr_rx=$(ip -s link show "$INTERFACE" | grep -A 1 RX | tail -n 1 | awk '{print $1}') # Calculate packets received in the last second packets_per_sec=$((curr_rx - prev_rx)) # Update the previous count for the next iteration prev_rx=$curr_rx # Track totals for the 10-second window count=$((count + 1)) total_packets=$((total_packets + packets_per_sec)) # Every 10 seconds, print the summary if [ $count -eq 10 ]; then avg_packets=$((total_packets / count)) echo "$(date '+%Y-%m-%d %H:%M:%S') - Average inbound packets/sec over last 10s: $avg_packets | Last second: $packets_per_sec" # Reset counters for the next window count=0 total_packets=0 fi done
What this script does:
- Tracks your specified network interface's inbound packet count
- Calculates how many packets arrive each second
- Every 10 seconds, it outputs the average packets per second over that window, plus the count from the most recent second
- Logs timestamps so you can correlate traffic spikes with potential DoS attempts
Run this command to give the script permission to run:
sudo chmod +x /usr/local/bin/packet-monitor.sh
Debian uses systemd by default, so this is the most reliable way to ensure your script starts automatically and restarts if it crashes.
- Create a systemd service file:
sudo nano /etc/systemd/system/packet-monitor.service - Paste this content into the file:
[Unit] Description=Inbound Packet Monitor for DoS Research After=network.target # Wait until the network is up before starting [Service] ExecStart=/usr/local/bin/packet-monitor.sh Restart=always # Restart the script if it stops unexpectedly User=root # Required to access network interface statistics StandardOutput=append:/var/log/packet-monitor.log # Save output to a log file StandardError=append:/var/log/packet-monitor.log # Save errors to the same log [Install] WantedBy=multi-user.target # Start when the system reaches multi-user mode - Save and exit the editor (Ctrl+O, Enter, then Ctrl+X in nano).
- Reload systemd to recognize the new service:
sudo systemctl daemon-reload - Enable the service to run on boot:
sudo systemctl enable packet-monitor.service - Start the service immediately to test it:
sudo systemctl start packet-monitor.service
Check the log file after 10 seconds to see if data is being recorded:
tail /var/log/packet-monitor.log
You should see lines like this:
2024-05-20 14:30:00 - Average inbound packets/sec over last 10s: 12 | Last second: 15
To test, you can send traffic to your machine (e.g., ping from another device) and watch the counts increase.
- If you don't see data, double-check your network interface name (run
ip linkto list all interfaces). - Ensure the script has root permissions—network stats require elevated access.
- If you want to track specific protocols (e.g., TCP, UDP) or ports later, you can modify the script to use
tcpdumpinstead ofip(e.g.,tcpdump -i $INTERFACE -c 0 -n tcp | wc -l), but start with the basic version first.
内容的提问来源于stack exchange,提问作者Aidan

