I’ve been in the habit of reading technical papers (one a day, sounds like a tablet). I believe, it would be a good idea to keep all of them in one place and so ‘Paper Of The Day’
Hardening the TCP/IP stack to mitigate/hanle SYN attacks
The paper brings in an interesting log of parameters that can be tuned/altered to protect servers from SYN flood attacks. Now it necessarily doesn’t mean that it will protect you cent percent but after tuning, the server will manage to survive a little better than the default configuration. Author has chosen to explain and give examples on RH Linux 7.3, Windows 2000, Sun Solaris 8 and HP-UX 11.0
It is quite interesting that these parameters are there still lot of servers (esp. web servers) are deployed with default configuration! Tweaking these settings aren’t ‘Rocket Science’ especially when you have documentation like this by good authors…
