Apr 2, 2018

UTM 週報 03/24




 Network Protection

Packet Filter / Firewall

TOP10 dropped source hosts

Total dropped packets: 23 477
Top

Source IP
User / Host
Packets
%
1
jp
DSL 26
4 957
21.11%
2
nl
213.227.141.73
213.227.141.73
443
1.89%
3
nl
191.101.167.73
191.101.167.x は五月中旬も登場
321
1.37%
4
lan
A12
279
1.19%
5
lan
LG 7
231
0.98%
6
ru
46.161.55.106
46.161.55.106
217
0.92%
7
gb
77.72.82.92
hostby.ups-gb.co.uk /24ネットは五月中旬も登場
207
0.88%
8
gb
77.72.82.80
206
0.88%
9
us
65.49.77.117
←五月中旬も登場
202
0.86%
10
gb
77.72.82.147
hostby.ups-gb.co.uk /24ネットは五月中旬も登場
201
0.86%

TOP10 dropped destination hosts

Total dropped packets: 23 477
Top

Destination IP
User / Host
Packets
%
1


External (WAN) (Address)
22 069
94.00%
2
lan
A22
597
2.54%
3
us
8.8.8.8
DNS Forwarder
69
0.29%
4
us
172.217.25.234
54
0.23%
5
us
216.58.220.238
51
0.22%
6
lan

int.200
49
0.21%
7
us
8.8.4.4
42
0.18%
8
lan
a23
35
0.15%
9
us
108.177.125.188
/16は五月中旬も
25
0.11%
10
us
64.233.189.188
/16は五月中旬も
25
0.11%

TOP10 dropped services

TOP10 dropped services
Total dropped packets: 23 477
Top Service Name Protocol Service Packets %
1 GRE - 4 957 21.11 %
2 MICROSOFT-DS TCP 445 4 265 18.17 %
3 TELNET TCP 23 2 568 10.94 %
4 MS-SQL-S TCP 1433 749 3.19 %
5 HTTPS TCP 443 336 1.43 %
6 SSH TCP 22 277 1.18 %
7 HTTP-ALT TCP 8080 275 1.17 %
8 TCP 8545 266 1.13 %
9 MYSQL TCP 3306 211 0.90 %
10 HTTP TCP 80 207 0.88 %


dropしてる中には、たまたまのケースが相当数あり。
アタックとは限らないので念のため

No comments: