IDS mailing list archives
Re: TCP: a practical question
From: "\"Zow\" Terry Brugger" <zow () acm org>
Date: Wed, 23 Jan 2008 08:22:08 -0800
Sorry for the late replies -- just getting caught up -- the four-way handshake is indeed not used on contemporary networks. In fact, I'm pretty sure it was never used much at all. In a true client/server architecture, it certainly doesn't make sense; but one must remember that it came from the same era as active FTP, so there was this sense that clients would become servers, and in such an environment, it's completely feasible that the SYNs could cross paths and essentially save a round-trip before data started flowing. I'm sure this was important when the Internet backbone was 56kbs, but not so much today. It's worth noting that I submitted an experimental RFC to the IETF, and in it I explicitly noted that I was not going to address the TCP four-way handshake because it wasn't used and one of the reviewers really flew off the handle and said I didn't understand anything about TCP and some other really unprofessional comments. I can only assume that it was whomever insisted on the inclusion of the four-way handshake in the first place, some 25 years ago, is still out there and active in the RFC process. Cheers, Terry #include <stddisclaim.h> ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
Current thread:
- TCP: a practical question snort user (Jan 17)
- Re: TCP: a practical question Adam Powers (Jan 18)
- Message not available
- Re: TCP: a practical question Fernando Gont (Jan 18)
- Re: TCP: a practical question crazy frog crazy frog (Jan 21)
- Message not available
- Re: TCP: a practical question Fernando Gont (Jan 21)
- Re: TCP: a practical question crazy frog crazy frog (Jan 21)
- Re: TCP: a practical question "Zow" Terry Brugger (Jan 23)
- Re: TCP: a practical question Fernando Gont (Jan 18)