官术网_书友最值得收藏!

Hardening your TCP/IP stack

For any given operating system, tuning of the TCP/IP stack can be performed by the system administrator. Changing the default values of TCP/IP stack variables provides another layer of protection and helps you to secure your hosts in a better way.

This is all about determining and making decisions about how many connections the server can maintain in a half-open state before TCP/IP triggers SYN flooding attack protection. This simply means that to configure the threshold value of the TCP connection, requests must be exceeded before SYN flood protection is triggered.

The following parameters can be adjusted on an operating system level to tune TCP/IP stacks. These are not only applicable to the operating system, but also to network devices such as firewalls and load balancers, which allow you to fine tune TCP stacks:

  • TcpMaxHalfOpen
  • TcpMaxHalfOpenRetried
  • TcpMaxPortsExhausted
  • TcpMaxConnectResponseRetransmissions

We will discuss DoS attacks in detail in the next section.

主站蜘蛛池模板: 即墨市| 富宁县| 永州市| 子长县| 汽车| 萨嘎县| 富宁县| 南安市| 镶黄旗| 瓮安县| 卫辉市| 香河县| 镇原县| 阳朔县| 桂东县| 神池县| 邻水| 彩票| 郸城县| 秦安县| 太仆寺旗| 凌云县| 南江县| 南江县| 红桥区| 抚松县| 尚义县| 右玉县| 科技| 星座| 共和县| 长沙县| 双辽市| 霸州市| 台东县| 广灵县| 昔阳县| 米脂县| 谷城县| 陆丰市| 武夷山市|