Re: Firewalling and network resource consumption while under attack

Alan Cox (alan@lxorguk.ukuu.org.uk)
Mon, 21 Sep 1998 20:45:39 +0100 (BST)


> I'm looking at discussing this in detail to come up with a solution so
> that a linux box doesn't keel over totally blind even under heavy inbound SYN
> attack. I'll do some studies of the network path and see if we can come
> up with a novel solution that is viable for 2.3.

The buffer has to be copied to main memory and the header checksummed whatever
happens. On a packet that matches the firewall no further processing is done

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/