DDoS DoS - SYN flood

State of IP spoofing (IP spoof)

Molto bello, un pò datato (ma abbastanza attuale)


Firewall con SYN-flood protection


Operating system defense


Notare (da http://man7.org/linux/man-pages/man7/tcp.7.html):

tcp_syncookies (Boolean; since Linux 2.2) Enable TCP syncookies.

The kernel must be compiled with CONFIG_SYN_COOKIES. Send out syncookies when the syn backlog queue of a socket overflows. The syncookies feature attempts to protect a socket from a SYN flood attack. This should be used as a last resort, if at all. This is a violation of the TCP protocol, and conflicts with other areas of TCP such as TCP extensions. It can cause problems for clients and relays. It is not recommended as a tuning mechanism for heavily loaded servers to help with overloaded or misconfigured conditions. For recommended alternatives see tcp_max_syn_backlog, tcp_synack_retries, and tcp_abort_on_overflow.

Post più popolari