On Thu, Jan 31, 2008 at 10:50:43AM -0600, Cache Hit wrote:
Depending on the traffic patterns of legit vs. attack the following idea
might work... use max-src-* with values that may create false positives
and overload into table which will still PASS. Now use
different values for max-src-* on pass rule to look for
longer term abuse and overload to . Effectively this lets you
do 2 stages of evaluation, at the price of taking a bit longer to block
attacks. Make sense?
--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation
| H. Peter Anvin | Re: [rft] s2ram wakeup moves to .c, could fix few machines |
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Ingo Molnar | [patch] PID namespace design bug, workaround |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
git: | |
| Eric Dumazet | Re: Multicast packet loss |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
