2017-02-06 109 views
1

從tomcat切換到另一個軟件包提供程序(bitnami - >官方debian)後,我遇到了問題。 似乎有人被擊中的請求我們的服務器(具有惡意):Tomcat 8:CPU使用率爲100%

59.111.29.6 - - [04/Feb/2017:16:17:58 +0000] "-" 400 - 

其中「 - 」是請求路徑,這與

Feb 04, 2017 4:17:58 PM org.apache.coyote.http11.AbstractHttp11Processor process 
INFO: Error parsing HTTP request header 
Note: further occurrences of HTTP header parsing errors will be logged at DEBUG level. 

它與CPU使用率增加重合一致。 服務器狀態顯示以下內容:

<h1>JVM</h1><p> Free memory: 355.58 MB Total memory: 833.13 MB Max memory: 2900.00 MB</p><table border="0"><thead><tr><th>Memory Pool</th><th>Type</th><th>Initial</th><th>Total</th><th>Maximum</th><th>Used</th></tr></thead><tbody><tr><td>Eden Space</td><td>Heap memory</td><td>34.12 MB</td><td>229.93 MB</td><td>800.00 MB</td><td>12.47 MB (1%)</td></tr><tr><td>Survivor Space</td><td>Heap memory</td><td>4.25 MB</td><td>28.68 MB</td><td>100.00 MB</td><td>2.22 MB (2%)</td></tr><tr><td>Tenured Gen</td><td>Heap memory</td><td>85.37 MB</td><td>574.51 MB</td><td>2000.00 MB</td><td>462.84 MB (23%)</td></tr><tr><td>Code Cache</td><td>Non-heap memory</td><td>2.43 MB</td><td>7.00 MB</td><td>48.00 MB</td><td>6.89 MB (14%)</td></tr><tr><td>Perm Gen</td><td>Non-heap memory</td><td>128.00 MB</td><td>128.00 MB</td><td>512.00 MB</td><td>52.57 MB (10%)</td></tr></tbody></table><h1>"http-nio-8080"</h1><p> Max threads: 200 Current thread count: 10 Current thread busy: 3 Keeped alive sockets count: 1<br> Max processing time: 301 ms Processing time: 71.068 s Request count: 10021 Error count: 2996 Bytes received: 0.00 MB Bytes sent: 3.18 MB</p><table border="0"><tr><th>Stage</th><th>Time</th><th>B Sent</th><th>B Recv</th><th>Client (Forwarded)</th><th>Client (Actual)</th><th>VHost</th><th>Request</th></tr><tr><td><strong>F</strong></td><td>1486364749526 ms</td><td>0 KB</td><td>0 KB</td><td>185.40.4.169</td><td>185.40.4.169</td><td nowrap>?</td><td nowrap class="row-left">? ? ?</td></tr><tr><td><strong>F</strong></td><td>1486364749526 ms</td><td>0 KB</td><td>0 KB</td><td>185.40.4.169</td><td>185.40.4.169</td><td nowrap>?</td><td nowrap class="row-left">? ? ?</td></tr><tr><td><strong>R</strong></td><td>?</td><td>?</td><td>?</td><td>?</td><td>?</td><td>?</td></tr><tr><td><strong>S</strong></td><td>36 ms</td><td>0 KB</td><td>0 KB</td><td>106.51.39.130</td><td>106.51.39.130</td><td nowrap>104.197.119.177</td><td nowrap class="row-left">GET /manager/status?org.apache.catalina.filters.CSRF_NONCE=072F9F6884D94C5D7B30D1D34CE61BD9 HTTP/1.1</td></tr><tr><td><strong>R</strong></td><td>?</td><td>?</td><td>?</td><td>?</td><td>?</td><td>?</td></tr></table><p>P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive</p><hr size="1" noshade="noshade"> 
 
<center><font size="-1" color="#525D76">

所以它看起來像一個內存不足的問題,並沒有(但我可能是錯的)。

如何阻止某人首先提出請求以避免我面臨的問題?我在tomcat上運行的webapp將HTTP方法限制爲GET/POST,但是如何將tomcat配置爲整體來限制它們?

回答

0

我勸你獲得你的服務器的線程轉儲:

jps -l

  • 使用獲得線程轉儲:

    • 用分離株Tomcat服務器的PID :

    kill -3 PIDjstack PID

    • 然後檢查線程轉儲,你應該找到粗加工螺紋
+0

的原因,我有轉儲[這裏](http://pastebin.com/fAZt1GRF)。我怎樣才能解釋這一點? – njLT

+0

我不確定它可能與JDK問題有關。 https://github.com/netty/netty/issues/327 sun.nio.ch.EPollArrayWrapper.poll(EPollArrayWrapper.java:269) –