官术网_书友最值得收藏!

Hardening your TCP/IP stack

For any given operating system, tuning of the TCP/IP stack can be performed by the system administrator. Changing the default values of TCP/IP stack variables provides another layer of protection and helps you to secure your hosts in a better way.

This is all about determining and making decisions about how many connections the server can maintain in a half-open state before TCP/IP triggers SYN flooding attack protection. This simply means that to configure the threshold value of the TCP connection, requests must be exceeded before SYN flood protection is triggered.

The following parameters can be adjusted on an operating system level to tune TCP/IP stacks. These are not only applicable to the operating system, but also to network devices such as firewalls and load balancers, which allow you to fine tune TCP stacks:

  • TcpMaxHalfOpen
  • TcpMaxHalfOpenRetried
  • TcpMaxPortsExhausted
  • TcpMaxConnectResponseRetransmissions

We will discuss DoS attacks in detail in the next section.

主站蜘蛛池模板: 河北省| 綦江县| 吉木乃县| 西充县| 三门县| 陆良县| 瑞安市| 静乐县| 延津县| 庆城县| 孝感市| 资溪县| 乌什县| 正蓝旗| 邵东县| 青神县| 青州市| 新津县| 来宾市| 白沙| 原阳县| 剑阁县| 海宁市| 万州区| 北流市| 阜新市| 周宁县| 定结县| 临汾市| 厦门市| 南漳县| 卓尼县| 衡南县| 济阳县| 固原市| 都昌县| 红安县| 绥宁县| 崇文区| 吉林省| 洮南市|