nanog mailing list archives
Re: router syn/syn-ack/ack alarming...
From: Michael Dillon <michael () memra com>
Date: Wed, 18 Sep 1996 16:01:41 -0700 (PDT)
On Wed, 18 Sep 1996, Vern Paxson wrote:
have something in their logs like SYN/ACK RATIO 33:1 POSSIBLE HACKER ATTACK which will make them sit up and take notice.I don't see how in reality to make the syn/syn-ack/ack ratio work soundly. It seems too easy for the cracker to synthesize bogus syn-ack's or ack's to manipulate the ratio however they please.
Wouldn't the ratio be calculated from outgoing SYN's and incoming ACK's? I can see that a sophisticated attacker could have a machine on another network sending incoming ACK's to balance the outgoing SYN's but I suspect this would be an extremely small percentage of attacks. Michael Dillon - ISP & Internet Consulting Memra Software Inc. - Fax: +1-604-546-3049 http://www.memra.com - E-mail: michael () memra com - - - - - - - - - - - - - - - - -
Current thread:
- Re: router syn/syn-ack/ack alarming..., (continued)
- Re: router syn/syn-ack/ack alarming... Mr. Jeremy Hall (Sep 17)
- Re: router syn/syn-ack/ack alarming... Perry E. Metzger (Sep 17)
- Re: router syn/syn-ack/ack alarming... Jeff Young (Sep 17)
- Re: router syn/syn-ack/ack alarming... Vadim Antonov (Sep 17)
- Re: router syn/syn-ack/ack alarming... Paul Ferguson (Sep 18)
- Re: router syn/syn-ack/ack alarming... Guy T Almes (Sep 18)
- Re: router syn/syn-ack/ack alarming... Michael Dillon (Sep 18)
- Re: router syn/syn-ack/ack alarming... Guy T Almes (Sep 18)
- Re: router syn/syn-ack/ack alarming... Justin W. Newton (Sep 18)
- Re: router syn/syn-ack/ack alarming... Vern Paxson (Sep 18)
- Re: router syn/syn-ack/ack alarming... Michael Dillon (Sep 18)
- Re: router syn/syn-ack/ack alarming... Larry J. Plato (Sep 18)
- Re: router syn/syn-ack/ack alarming... George Herbert (Sep 18)
- Re: router syn/syn-ack/ack alarming... Mark A. Fullmer (Sep 18)
- Re: router syn/syn-ack/ack alarming... Michael Dillon (Sep 18)
- Re: router syn/syn-ack/ack alarming... Michael Dillon (Sep 18)
- Re: router syn/syn-ack/ack alarming... Michael Dillon (Sep 18)
- Re: router syn/syn-ack/ack alarming... Curtis Villamizar (Sep 18)
- Re: router syn/syn-ack/ack alarming... George Herbert (Sep 18)