nanog mailing list archives
Re[2]: SYN floods (was: does history repeat itself?)
From: pcalhoun () usr com (Pat Calhoun)
Date: Mon, 9 Sep 1996 13:19:18 -0500
Perry, This is actually quite simple to implement on Dial Access Routers, and obviously this is the best place to add the filtering. Pat R. Calhoun e-mail: pcalhoun () usr com Project Engineer - Lan Access R&D phone: (847) 933-5181 US Robotics Access Corp. ______________________________ Reply Separator _________________________________ Subject: Re: SYN floods (was: does history repeat itself?) Author: "Perry E. Metzger" <perry () piermont com> at Internet Date: 9/9/96 1:19 PM Re: SYN floods PANIX, a large public access provider in New York, was badly hit with SYN flood attacks from random source addresses over the last few days. It nearly wrecked them. I think its time for the larger providers to start filtering packets coming from customers so that they only accept packets with the customer's network number on it. Yes, its a load on routers. Yes, its nasty for the mobile IP weenies. Unfortunately, the only known way to stop this. Many TCPs go belly up as soon as they get SYN flooded -- its a defect in the protocol design, and other than Karn style anti-clogging tokens ("cookies") being put into a TCP++ and mass implemented worldwide soon, the only reasonable way to stop this sort of terrorism is provider filtering. Perry
Attachment:
RFC822 message headers
Description: cc:Mail note part
Current thread:
- Re[2]: SYN floods (was: does history repeat itself?) Pat Calhoun (Sep 09)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alec H. Peterson (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alexis Rosen (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alec H. Peterson (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alexis Rosen (Sep 10)
- Message not available
- Re: Re[2]: SYN floods (was: does history repeat itself?) Sharif Torpis (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alec H. Peterson (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alexis Rosen (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Alec H. Peterson (Sep 10)
- Re: Re[2]: SYN floods (was: does history repeat itself?) John G. Scudder (Sep 12)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Joel Gallun (Sep 12)
- Re: Re[2]: SYN floods (was: does history repeat itself?) Michael Dillon (Sep 12)