Skip to content

Commit deedaeb

Browse files
committed
add some details for estimates
1 parent f661a1d commit deedaeb

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

crowdsec-docs/unversioned/console/remediation_metrics.mdx

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,11 @@ This section highlights the amount of malicious traffic that has been remediate
4444
- **Raw data** represents actual traffic dropped by your remediation components (bouncers), powered by blocklists and security engines.
4545
- **Estimated data** is calculated by applying a coefficient to the raw metrics to provide a projected view of saved resources.
4646

47+
The data estimate is based on the following considerations:
48+
* For OSI L4 (firewall level) bouncers: 7 blocked packets make up about 1 blocked attack attempt (due to tcp-syn retries)
49+
* For OSI L7 (application level) bouncers: 1 blocked request makes up about 1 blocked attack attempt
50+
* 1 blocked attack attempt would result in 10 actual attacks if the attacker wasn't blocked, as most attackers will try a sequence of exploits in rapid succession.
51+
4752
![Traffic Discarded](/img/console/remediation_metrics/rc-metrics-traffic-discarded.png)
4853

4954
Below the graph, you’ll find a **blocklist breakdown**, ordered by the amount of traffic each list helped block.

0 commit comments

Comments
 (0)