Re: Other possible protection against RST/SYN attacks

[ Available lists | Index of freebsd-security | Month of Apr 2004 | Week of 22 Apr 2004 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Neo-Vortex <root@Neo-Vortex.Ath.Cx>
Date
22 Apr 2004 01:00:20
Subject
Re: Other possible protection against RST/SYN attacks
Message-ID
20040422175239.E16696@Neo-Vortex.Ath.Cx

In reply to

[ Hide this part ]
Heres my view on this hole thing and a solution to it:

Take a step back from the problem, how is it caused? Spoofing of packets.
Numerous vulnerabilities come from spoofed packets, and no doubt there
will be more to come.

If the ability to spoof packets on the internet was stopped, it would be
much easier to fight such things, because they would not be possible.

How to stop the spoofing? get ISPs to allow their customers to only send
IP packets with the src address the same as their allocated ip(s) and drop
the rest.

If they all took the time to impliment this, they would not have to worry
so much about patches later on because the probability of the packets
being spoofed becomes so low.

This could also be implimented on a higher level too (Asin the higher
level ISPs doing similiar stuff)


Elapsed time: 0.136 seconds