Please how one can configure DDoS deflate to deny low volume attacks?


Installing DDoS Deflate:

Probably worth using improved version of DDoS deflate here:
Following tutorial is for the original version with lower number of features.

wget;chmod 0700;./

Then whitelist your IP or other important IP that should be ignored and that can produce many connections like a FTP (example IP: Just add one IP per line:
vi /usr/local/ddos/ignore.ip.list
LEGEND fo "vi" editor: "a" = start editing; "Ctrl+C" stop editing; ":wq" save changes and quit; ":q!" dont save and quit

Then open deflate file:
vi /usr/local/ddos/;

netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr > $BAD_IP_LIST
netstat -ntu | grep ':' | awk '{print $5}' | sed 's/::ffff://' | cut -f1 -d ':' | sort | uniq -c | sort -nr > $BAD_IP_LIST
below line:
echo "$CURR_LINE_IP with $CURR_LINE_CONN connections" >> $BANNED_IP_MAIL
add following new line:
echo -e "\n$CURR_LINE_IP\n$CURR_LINE_IP\n$CURR_LINE_IP\n\n $(/usr/bin/whois $CURR_LINE_IP|grep -iv whois)" >> $BANNED_IP_MAIL
(so the e-mail contains some more useful details about the banned IP)

then open deflate conf. file:
vi /usr/local/ddos/ddos.conf


Uninstalling DDoS deflate:
wget;chmod 0700 uninstall.ddos;./uninstall.ddos
Please do you have any suggestions to this configuration or how do you do it?