From: Ross Vandegrift <ross@kallisti.us>
To: Andi Kleen <andi@firstfloor.org>
Cc: Glenn Griffin <ggriffin.kernel@gmail.com>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] Add IPv6 support to TCP SYN cookies
Date: Tue, 5 Feb 2008 16:23:35 -0500 [thread overview]
Message-ID: <20080205212335.GA11287@kallisti.us> (raw)
In-Reply-To: <20080205201106.GB26150@one.firstfloor.org>
On Tue, Feb 05, 2008 at 09:11:06PM +0100, Andi Kleen wrote:
> > The problem is that any reasonably recent PC can generate enough
> > forged SYN packets to overwhelm reasonable SYN queues on a much more
> > powerful server.
>
> Have you actually seen this with a recent kernel in the wild or are
> you just talking theoretically?
>
> Linux uses some heuristics to manage the syn queue that should
> still ensure reasonable service even without cookies under attack.
> Also SYN-RECV sockets are stored in a special data structure optimized
> to use minimal resources.
>
> It is far from the classical head drop method that was so vunerable
> to syn flooding.
I work at a hosting company and we see these kinds of issues in the
real world fairly frequently. I would guess maybe a monthly basis.
The servers where we have seen this are typically running RHEL 4 or 5
kernels, so I can't really speak to how recent the kernel is in this
specific term.
If I can find a box that we could temporary get a kernel.org kernel
on, I'll see if I can get a real comparison together. We have
collected a few of the more effective attack tools that have been left
on compromised systems, so it wouldn't be too difficult to get some
numbers.
--
Ross Vandegrift
ross@kallisti.us
"The good Christian should beware of mathematicians, and all those who
make empty prophecies. The danger already exists that the mathematicians
have made a covenant with the devil to darken the spirit and to confine
man in the bonds of Hell."
--St. Augustine, De Genesi ad Litteram, Book II, xviii, 37
next prev parent reply other threads:[~2008-02-05 21:23 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-02-04 23:01 [PATCH] Add IPv6 support to TCP SYN cookies Glenn Griffin
2008-02-05 15:55 ` Andi Kleen
2008-02-05 15:42 ` Alan Cox
2008-02-05 16:39 ` Andi Kleen
2008-02-05 16:03 ` Alan Cox
2008-02-05 16:48 ` Andi Kleen
2008-02-05 16:14 ` Alan Cox
2008-02-05 20:50 ` Willy Tarreau
2008-02-05 18:29 ` Glenn Griffin
2008-02-05 19:25 ` Ross Vandegrift
2008-02-05 20:11 ` Andi Kleen
2008-02-05 21:23 ` Ross Vandegrift [this message]
2008-02-06 8:53 ` Andi Kleen
2008-02-07 19:44 ` Ross Vandegrift
2008-02-08 12:07 ` Andi Kleen
2008-02-12 20:38 ` Ross Vandegrift
2008-02-05 20:02 ` Andi Kleen
2008-02-05 20:39 ` Evgeniy Polyakov
2008-02-05 20:53 ` Andi Kleen
2008-02-05 21:50 ` Evgeniy Polyakov
2008-02-05 21:20 ` Alan Cox
2008-02-05 21:52 ` Evgeniy Polyakov
2008-02-05 21:20 ` Willy Tarreau
2008-02-05 22:05 ` Alan Cox
2008-02-06 1:52 ` Glenn Griffin
2008-02-06 7:50 ` Andi Kleen
2008-02-06 17:36 ` Glenn Griffin
2008-02-06 18:45 ` Andi Kleen
2008-02-06 23:03 ` Glenn Griffin
2008-02-06 9:13 ` Evgeniy Polyakov
2008-02-06 18:30 ` Glenn Griffin
2008-02-07 7:24 ` Evgeniy Polyakov
2008-02-07 9:40 ` Eric Dumazet
2008-02-08 5:32 ` Glenn Griffin
2008-02-08 5:49 ` Glenn Griffin
2008-02-11 16:07 ` YOSHIFUJI Hideaki / 吉藤英明
2008-02-18 23:45 ` Glenn Griffin
2008-02-13 7:31 ` YOSHIFUJI Hideaki / 吉藤英明
2008-02-05 19:57 ` Jan Engelhardt
2008-02-05 21:25 ` Alan Cox
-- strict thread matches above, loose matches on Subject: below --
2008-02-04 23:01 Glenn Griffin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080205212335.GA11287@kallisti.us \
--to=ross@kallisti.us \
--cc=andi@firstfloor.org \
--cc=ggriffin.kernel@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox