BSDCan2017 - 0722d
BSDCan 2017
The Technical BSD Conference
Speakers | |
---|---|
Henning Brauer |
Schedule | |
---|---|
Day | Talks #2 - 10 June - 2017-06-10 |
Room | DMS 1120 |
Start time | 11:15 |
Duration | 01:00 |
Info | |
ID | 816 |
Event type | Lecture |
Language used for presentation | English |
tcp synfloods
an old yet current problem, and improving pf's response
TCP Synfloods have been with us for decades.
Why are they still a problem?
What countermeasures have been implemented in network stacks?
How can we improve pf's synflood handling?
I'm working on pf to detect synfloods and then cope better with them then we already do.
I'll explain why this so old problem is still current and hasn't been solved.
We'll then look at common countermeasures, their effectivity, and their downsides.
And eventually, I'll detail the upcoming changes to pf improving synflood resiliency for pf itself and protection for the hosts behind.