惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
MyScale Blog
MyScale Blog
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
MongoDB | Blog
MongoDB | Blog
I
InfoQ
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Building a Real-Time HTTP Anomaly Detection Engine for Ne...
Fredrick Any · 2026-04-29 · via DEV Community

Fredrick Anyanwu

For this project, I deployed Nextcloud behind Nginx and built a Python daemon that performs real-time anomaly detection on incoming HTTP traffic.

The key requirement was to avoid static assumptions and instead learn “normal” traffic behavior continuously.

Stack and deployment model

  • VPS: Linux (2 vCPU / 2 GB RAM minimum)
  • Nextcloud container (provided image)
  • Nginx reverse proxy
  • Python detector daemon
  • Slack Incoming Webhooks
  • iptables for active mitigation
  • Live dashboard (Flask) Nginx writes JSON access logs to /var/log/nginx/hng-access.log, stored in a named Docker volume HNG-nginx-logs shared read-only with detector.

Structured logging

Nginx access logs include at minimum:

source_ip

  • timestamp
  • method
  • path
  • status
  • response_size This simplifies parsing and keeps the detector robust under load.

Sliding windows (deque-based)

I maintain two 60-second windows:

  • Global request timestamps
  • Per-IP request timestamp deques For each request:
  1. append timestamp
  2. evict entries older than 60 seconds
  3. compute rate from deque length This is a true rolling window implementation (not a minute bucket counter).

Rolling baseline implementation

I keep a rolling 30-minute history of per-second counts and recalculate every 60 seconds.

Computed metrics:

  • mean request count
  • standard deviation
  • baseline error rate I also maintain hourly slots and prefer current-hour baseline once that slot has sufficient points. Floor values protect against near-zero baseline behavior.

Detection logic

An anomaly triggers when either condition is true:

  • z_score > 3.0
  • current_rate > 5 * baseline_mean Error-surge path:

if an IP’s error activity significantly exceeds baseline error behavior, per-IP thresholds are tightened automatically.

Mitigation workflow

Per-IP anomaly:

  • insert firewall rule:
  • iptables -I INPUT -s -j DROP
  • send Slack BAN alert
    Global anomaly:

  • send Slack GLOBAL alert

  • no broad blocking
    Unban policy (backoff):

  1. 10m
  2. 30m
  3. 2h
  4. permanent for repeated offenders Every unban emits Slack and audit events.

Dashboard and audit trail

Dashboard refreshes every 3 seconds and exposes:

  • global req/s
  • top source IPs
  • banned IPs
  • CPU/memory
  • effective baseline stats
  • uptime Audit log format:

[timestamp] ACTION ip | condition | rate | baseline | duration

Actions include: BAN, UNBAN, BASELINE, ALERT.

Practical outcomes

This project demonstrates: