SYNPROXY: a cheap anti-DoS Solution

Source: Internet
Author: User

DoS attacks are an eternal problem. Although professional firewall and Server Load balancer gateway devices can effectively defend against DoS attacks, however, hackers prefer the combination of x86 + GNU/Linux for the simple reason: cheap enough.


 

The new feature of SYNPROXY was finally added to Linux kernel 3.13. This module is a link-tracking-based netfilter extension, the main task is to mark the initial SYN packet from the client as UNTRACKED and then directly import the "SYNPROXY" action of iptables (similar to ACCEPT, NFQUEUE, and DROP ), at this time, the kernel will assume the role of the gateway device and continue the TCP regular handshake process with the client. SYNPROXY will wait until the final ACK (three-way handshake) after the cookie is verified to be valid, the package will start to enter the target end.

Data from the developer Jesper Dangaard Brouer shows that SYNPROXY is very effective against syn flood dos attacks. Today, I also tested SYNPROXY DoS In Debian and SLES-12-beta2, the general result is that hping3 and metasploit are used for testing. After SYNPROXY is enabled, ksoftirq usage will be reduced from 8% to 3%.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.