Re: PF - using overload for port 80 attacks/floods

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Cache Hit <cachehit@...>
Cc: <misc@...>
Date: Thursday, January 31, 2008 - 2:11 pm

On Thu, Jan 31, 2008 at 10:50:43AM -0600, Cache Hit wrote:

Depending on the traffic patterns of legit vs. attack the following idea
might work... use max-src-* with values that may create false positives
and overload into table which will still PASS. Now use
different values for max-src-* on pass rule to look for
longer term abuse and overload to . Effectively this lets you
do 2 stages of evaluation, at the price of taking a bit longer to block
attacks. Make sense?

--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
PF - using overload for port 80 attacks/floods, Cache Hit, (Thu Jan 31, 12:50 pm)
Re: PF - using overload for port 80 attacks/floods, Darrin Chandler, (Thu Jan 31, 2:11 pm)
Re: PF - using overload for port 80 attacks/floods, Peter N. M. Hansteen, (Fri Feb 1, 3:30 am)
Re: PF - using overload for port 80 attacks/floods, Cache Hit, (Fri Feb 1, 12:23 pm)