Random Network Filtering Tricks
Created on Saturday 13 July 2002 by Fabrice MARIE
Table of Contents
- Random Network Filtering Tricks
- Introduction
- No Dangerous Source Spoofing
- No ICMP tricks
- Mitigate SYN Floods Locally/Avoid blind connections
- Stop remote guessing of machine's uptime/OS fingerprint
- Don't get tricked with redirects
- Log Martians
- Stop Traceroutes (2)
- Stop Systematic Portscans
- Stop Simple Denials Of Service
- Remove These Nasty IPv4 Options
- Get Rid Of Bad Packets
- Limit The Time At Which Ressources Are Available
- Put A Size Quota
- Keeping The Bad Guys Out
- Drop Silently Traffic That You Expect To Refuse
- Anti-trick: The 'string' Match
- Randomize It !
- Simulate Network Failure
- Patch-O-Matic
- Patches That You Should Apply
- Netfilter Vs. ipfilter
- Netfilter Future
- Last words...
- Links
- Thanks