查看所有80連接埠的串連數
1netstat-nat|grep-i"80"|wc-l
對串連的IP按串連數量進行排序
1netstat-ntu |awk'{print $5}'|cut-d: -f1 |sort|uniq-c |sort-n
查看TCP串連狀態
123456netstat-nat |awk'{print $6}'|sort|uniq-c|sort-rnnetstat-n |awk'/^tcp/ {++S[$NF]};END {for(a in S) print a, S[a]}'netstat-n |awk'/^tcp/ {++state[$NF]}; END {for(key in state) print key,"t",state[key]}'netstat-n |awk'/^tcp/ {++arr[$NF]};END {for(k in arr) print k,"t",arr[k]}'netstat-n |awk'/^tcp/ {print $NF}'|sort|uniq-c|sort-rnnetstat-ant |awk'{print $NF}'|grep-v'[a-z]'|sort|uniq-c
查看80連接埠串連數最多的20個IP
12netstat-anlp|grep80|greptcp|awk'{print $5}'|awk-F:'{print $1}'|sort|uniq-c|sort-nr|head-n20netstat-ant |awk'/:80/{split($5,ip,":");++A[ip[1]]}END{for(i in A) print A,i}'|sort-rn|head-n20
用tcpdump嗅探80連接埠的訪問看看誰最高
1tcpdump -i eth0 -tnn dst port 80 -c 1000 |awk-F"."'{print $1"."$2"."$3"."$4}'|sort|uniq-c |sort-nr |head-20
尋找較多time_wait串連
1netstat-n|grepTIME_WAIT|awk'{print $5}'|sort|uniq-c|sort-rn|head-n20
尋找較多的SYN串連
1netstat-an |grepSYN |awk'{print $5}'|awk-F:'{print $1}'|sort|uniq-c |sort-nr |more