FastNetMon – very fast DDoS analyzer
github.com
github.com
Watch out when implementing this stuff, it goes wrong way too often. At this point I have hard time not literally screaming at DC techs when my servers get suspended for "UDP flooding"[1] each other.
[1] Otherwise known as OpenVPN
Might give it a look.... even the screenshot of the real time top talkers looks like something interesting for the NOC to have up.
"This personal computer looks like a nice alternative for companies with a small budget for a mainframe who would otherwise have nothing at all"
Then once an attack has been identified you want to specify mitigation policies: Customer A gets full mitigation, but customer B needs to be blackholed instead. If an attack is smaller than 10Gbps you want to simply insert some flowspec rules into your edge routers, but if the attack pattern is too random you will have to redirect a /32 to a specialized scrubbing device instead. Larger attacks you might want to announce through a DDoS protection service so you announce the /24 containing that IP address to your DDoS protection service to reduce bandwidth on your own uplinks, and so on. I could go on, I hope you get the idea :)
As next step I could offer custom rules for mitigation depending on host group name.