router syn/syn-ack/ack alarming...

Vadim Antonov avg at quake.net
Wed Sep 18 20:57:52 UTC 1996


Michael Dillon <michael at memra.com> wrote:

>This ratio detection
>doesn't need to shutdown anything, just syslog the fact so that admins
>have something in their logs like SYN/ACK RATIO 33:1 POSSIBLE HACKER
>ATTACK which will make them sit up and take notice.

Ah, you're an optimist.

Most sysadmins would simply ignore whatever warnings they get as
long as their internal users aren't complaining.

And half of them wouldn't know what SYN/ACK ratio is.

--vadim





More information about the NANOG mailing list