[Fiware-lab-federation-nodes] Suspicious network traffic from "burkhard-krome"

Jan Kundrát jan.kundrat at cesnet.cz
Tue Mar 1 13:25:16 CET 2016


Dear colleagues,
our IDS department has detected suspicious network patterns related to a VM 
owned by user_id burkhard-krome (tenant_id 
77480c33ee364afc9a6379b83e8dadc0).

We're seeing sustained packet rates of about 140k packets/s, with more than 
3TB of data transferred since Friday. The pattern appears to be consistent 
with a DoS traffic.

In the meanwhile, we have paused both VMs that the user was running here in 
Prague. What is the recommended form of notification to the user? What is 
the procedure for blocking their access to the nodes? What are the next 
steps that we should take?

With kind regards,
Jan



More information about the Fiware-lab-federation-nodes mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy