{"id":1376,"date":"2023-01-15T02:00:18","date_gmt":"2023-01-15T07:00:18","guid":{"rendered":"http:\/\/www.rfdm.com\/blog\/?p=1376"},"modified":"2023-03-24T21:10:16","modified_gmt":"2023-03-25T01:10:16","slug":"jan-14-2023-unacknowledged-syns-by-country","status":"publish","type":"post","link":"https:\/\/www.rfdm.com\/blog\/?p=1376","title":{"rendered":"Jan 14, 2023 Unacknowledged SYNs by country"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It&#8217;s sometimes interesting to look at how different a single day might be versus the longer-term trends.  And to see what happens when you make changes to your pf rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I added all RU networks I was blocking from ssh to the list blocked for everything.  I also fired up a torrent client on my desktop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RU moving up the list versus the previous 5 days is no surprise; a good portion of traffic I receive from RU is port scanning.  But I&#8217;ll have to look to see what caused the CZ numbers to climb.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I think the only interesting thing about the torrent client is that I should do something to track UDP in a similar manner as I track TCP.  If I have a torrent client running, I will wind up with a lot of UDP traffic (much of it directed to port 6881 on this day), and will respond with ICMP port unreachable.  To some extent this is a burden on my outbound bandwidth, but on the other hand it will allow me to add an easy new tracker to mcflowd: &#8220;to whom am I sending ICMP port unreachables?&#8221;.  Of course, UDP is trivially spoofed, so I don&#8217;t truly know the source of the UDP.<\/p>\n\n\n\n<div height=\"80%\"><canvas id=\"synChart\" style=\"max-height:100%;height:980;width:100%;display:flex;flex-flow:column;\"><\/canvas>\n<\/div>\n\n<script src=\"https:\/\/cdn.jsdelivr.net\/npm\/chart.js\"><\/script>\n\n<script>\n\nnew Chart(document.getElementById('synChart'), {type:'bar',data:{labels: ['CZ','US','GB','RU','TW','HK','CN','PH','NA','CA','SK','AU','NL','SR','PT','IL','ES','IN','BR','TR','ZA','SG','SE','RO','GR'],datasets:[{label:'Unacknowledged SYNs by country',data:[41472,37802,27899,24089,21104,18006,15301,13334,12726,12280,11512,11187,10835,10540,9857,7827,7573,6286,5603,4808,4524,4184,4124,4019,3885],borderWidth:1,backgroundColor:\"rgba(255,0,0,0.7)\"}]},options:{responsive:true,plugins:{title: {\n                display: true,\n                text: 'Jan 14, 2023',color:'white',font:{size: 14}\n            },legend:{labels:{color:\"white\"}}},scales:{x:{ticks:{autoSkip:false,color:'white'}},y:{ticks:{color:'white'}}},y:{beginAtZero:true}}});\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s sometimes interesting to look at how different a single day might be versus the longer-term trends. And to see what happens when you make changes to your pf rules. I added all RU networks I was blocking from ssh to the list blocked for everything. I also fired up a torrent client on my &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.rfdm.com\/blog\/?p=1376\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Jan 14, 2023 Unacknowledged SYNs by country&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[85,12,1],"tags":[],"class_list":["post-1376","post","type-post","status-publish","format-standard","hentry","category-network-security","category-software-development","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1376"}],"version-history":[{"count":27,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1376\/revisions"}],"predecessor-version":[{"id":1436,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1376\/revisions\/1436"}],"wp:attachment":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}