Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SYN floods - possible solution
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Sun, 15 Sep 1996 19:06:22 +1000 (EST)
To: william @ neosoft . com (William S. Duncanson)
Cc: Todd . Truitt @ evolving . com, firewalls @ GreatCircle . COM
In-reply-to: <2 . 2 . 32 . 19960913215259 . 00303afc @ localhost> from "William S. Duncanson" at Sep 13, 96 04:52:59 pm

In some mail from William S. Duncanson, sie said:
> 
> At the time that I was made aware of the attack by the server's
> administrator, and started monitoring the traffic on the router, we were
> getting about 20 syn's per second from such improbable addresses as
> 0.122.205.10 and 255.96.127.33.  These are just from the 20-25 seconds that
> I actually tee'd the tcpdump, and occured within less than a second of each
> other.  Noticing those two was how I confirmed the administrator's suspicion
> that there was source address spoofing going on.

Hmmm, if the addresses are truely random, a number can be dropped without
any trouble:

deny proto tcp src 224.0.0.0/3 dst any

(or whatever the equivalent for your access list is)

Multicast TCP doesn't exist, and anything above that isn't assigned.

I don't know how many class A networks are still in use (35, 18...) but
depending on the number, it maybe viable to setup a rule like

deny proto tcp src 0.0.0.0/1 dst any

and create other access lists for the smaller networks to get in, if that
is part of your default access list.

Darren


References:
Indexed By Date Previous: Re: SparcLinux/OS for a secure bastion host !
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: SparcLinux/OS for a secure bastion host !
From: alan @ lxorguk . ukuu . org . uk (Alan Cox)
Indexed By Thread Previous: Re: SYN floods - possible solution
From: "William S. Duncanson" <william @ neosoft . com>
Next: Gauntlet and restricting email
From: Erik Van Riper <geek @ willent . com>

Google
 
Search Internet Search www.greatcircle.com