It'll help you with logs but certainly not provide the same peace of mind that key auth or even post login TOTP provides.
Cool project nevertheless.
It'll help you with logs but certainly not provide the same peace of mind that key auth or even post login TOTP provides.
Cool project nevertheless.
Obviously my approach would be somewhat involved but I'd imagine this would mostly be intended to protect against someone who may already have likely password candidates, rather than just random scanners.
Sadly, source level routing on routers is slow, and even if it wasn't, I wasn't sure how to automatically block said IPs at the router level.
Scanning every single TCP port on a host will require 65536 packets, those packets will all be about 40 bytes in size. That's only 2.6 megabytes, so on a 100Mbit link that should take around 200ms to send.
This is a pretty trivial exercise to implement yourself, but for pre-existing tools you can look at masscan and zmap. However, these will not provide the version detection nmap does.
No it isn't, nmap is ridiculously slow no matter what you do.
The only thing it does well is version detection, but you can do that too way faster.
If you specifically need nmaps version detection, sure use it. Otherwise you might be better off using masscan, it tends to do a pretty good job even with the default banner grabbing.