freebsd 6 deny ddos

本文探讨了FreeBSD系统如何通过syncache和syncookie两种机制来抵御SYN洪水攻击。即使关闭syncookie功能,系统似乎仍然使用该机制进行防御。
Yesterday, I have a test on FreeBSD 6 with synflooding. FreeBSD behaved very well but strange.

Though net.inet.tcp.syncookies is on by default, I set it to zero to disable syncookie, it seems that the FreeBSD was still using syncookie. I don't know if it's the normal operation. I'll do some dig into the source to see what will happen when set the MIB to 0.

After all, you should enable device polling before any other operations.
 
I've explored the source code. FreeBSD has implemented two mechanisms in the kernel, one is syncache, the other is syncookie. If you tuned syncookie on, the kernel will firstly find the matching entry in the syncache when received ACK packets, if no matching entry found, the kernel will do a check on the returned SN. If you turned the syncookie off, you will probably sufferring from the synflood (D)?DOS attack
 
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值