NetFilter
[Top] [All Lists]

Re: syn DDoS attack solution

To: netfilter@lists.netfilter.org
Subject: Re: syn DDoS attack solution
From: "Ethy H. Brito" <ethy.brito@inexo.com.br>
Date: Fri, 1 Jun 2007 20:09:10 -0300
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <466090CA.2050806@rtij.nl>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: InterNexo Ltda.
References: <465EF582.4070904@bgs.hu> <015e01c7a3bf$64fbe7e0$2ef3b7a0$@COM> <465FEA82.709@bgs.hu> <007101c7a45d$bc50e380$34f2aa80$@COM> <466090CA.2050806@rtij.nl>
Sender: netfilter-bounces@lists.netfilter.org
On Fri, 01 Jun 2007 23:34:02 +0200
Martijn Lievaart <m@rtij.nl> wrote:

> > Then your original description was incorrect or at least inadequate. It has
> > nothing to do with SYN as originally suggested since an ESTABLISHED
> > connection has blown past SYN, through SYN/ACK and by ACK. It has completed
> > the TCP handshake, as you note above. A SYN attack/flood would stop after
> > sending the initial SYN and leave the connection half-open to exhaust the
> > half-open buffers.
> >   
> 
> An connection is in the ESTABLISHED state once a packet has been seen. 
> So once the SYN is seen, the state is ESTABLISHED.

I think you meant "So once the SYN is seen, the state is NEW".

The state will change to ESTABLISHED as soon as netfiletr sees the SYN+ACK
response.

My 2 cents.
Cheers.

Ethy




<Prev in Thread] Current Thread [Next in Thread>