From: Panagiotis Atmatzidis Date: 2009-12-08T01:40:55+09:00 Subject: Re: awk to ruby 1.9 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, On 07 Δεκ 2009, at 12:50 π.μ., Robert Klemme wrote: > On 06.12.2009 20:01, Panagiotis Atmatzidis wrote: >> Good evening (it's 8:48 pm here)! > > Are you in Greece? It seems the country is shaken by riots currently. I hope, no more people get killed in the course of action. It's enough that a young boy died a year ago. Yes I am Greek. True, it's a mess. This years, all the riots was just a reminder of last year's chaos. Where I live however, it's okay, no broken stores or burned cars around here, nothing happens. :-) > >> True. There is 1 ip per line and some duplicates but there's a catch also. There are some IP's that are captured more than 1 time with the "Ban" flag. Which means that they were captured in a different time. Fail2ban blocks the IP for a couple of minutes in order to avoid the password brute-force which is taking place. After 3 minutes Unbans the ip. So the usual kind of log is this: >> 2009-11-15 15:19:35,222 fail2ban.actions: WARNING [ssh-ipfw] Ban 195.66.191.75 >> 2009-11-15 15:29:35,643 fail2ban.actions: WARNING [ssh-ipfw] Unban 195.66.191.75 >> 2009-11-16 07:46:59,854 fail2ban.actions: WARNING [ssh-ipfw] Ban 203.172.184.130 >> 2009-11-16 07:57:00,085 fail2ban.actions: WARNING [ssh-ipfw] Unban 203.172.184.130 >> [*I leave the IP's intact because these are actual SSH attacks and... if the admin don't care for his host, neither do I.] >> So at this point, I need really to display duplicates and maybe issue a bold warning when an IP appears more than 5 times. It means that your host is probably *targeted*. > > In that case you probably want to use a Hash for counting like this > > ips = Hash.new 0 > > ... > if ips[ip] += 1 >= 5 > $stderr.puts "WARNING: potential attack from #{ip}!" > end > ... I used a similar approach, which is used by the book also. I've created another file (like a library of sorts) and created new hash which keeps track of the number an IP shows up. # statistics class Stats def self.count_ip_display(ips) counts = Hash.new(0) for ip in ips counts[ip] += 1 end sort = counts.sort_by {|ip, display| display} #top_ten = sort.last(10).reverse #top_ten len = sort.length ips sort end end I see that your sample above, is like " Hasn.new 0". I guess that's just another syntax for Hash.new(0) right? > >>> Welcome to the wonderful world of Ruby! >> Thanks!!! THe learning process is for sure much easier than Objective-C, the syntax much more straight forward, but some concepts I'm still struggling to understand them! Thanks for your reply though, it was very enlightening. > > You're welcome! > >> PS. yes I know I can install SNORT and get over it, but it's much funnier creating your own programs! > > Absolutely! :-) > >> Oh, this mailing list is *really* good :-) > > Thanks a bunch! This group is among the friendlies places I know for exchange of technical thoughts. > > Kind regards > > robert Yes, it's nice to feel good with other people. Having a Linux background I've faced too many "elite-driven" hostile communities in the past to understand the value of a healthy (of trolls, etc) ML > > -- > remember.guy do |as, often| as.you_can - without end > http://blog.rubybestpractices.com/ > Panagiotis (atmosx) Atmatzidis email: atma@convalesco.org URL: http://www.convalesco.org GnuPG ID: 0xFC4E8BB4 gpg --keyserver x-hkp://pgp.mit.edu --recv-keys 0xFC4E8BB4 - -- The wise man said: "Never argue with an idiot. They bring you down to their level and beat you with experience." -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.12 (Darwin) iEYEARECAAYFAksdMBAACgkQrghUb/xOi7SbgACggQbt+oqU08lU4jT566JF0S2s uDsAnRIJEn3dbqQrin+mQXHJItz8vVsF =H/tM -----END PGP SIGNATURE-----