Get the App
SLTechnology News&Howtos  ›  Development  › 

How does Linux defend against SYN attacks

Shulou Source: shulou.com Published: 2022-06-01 21:54:17 10月04日 Update

This article mainly explains "how to defend against SYN attacks by Linux". Interested friends may wish to have a look at it. The method introduced in this paper is simple, fast and practical. Let's let the editor take you to learn how to defend against SYN attacks by Linux.

1. Default syn configuration sysctl-a | grep _ syn net.ipv4.tcp_max_syn_backlog = 1024 net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_synack_retries = 5 net.ipv4.tcp_syn_retries = 5tcp_max_syn_backlog is the length of the SYN queue. Increasing the length of the SYN queue can accommodate more network connections waiting for connections. Tcp_syncookies is a switch, whether to turn on the SYN Cookie function, this function can prevent some SYN attacks. Tcp_synack_retries and tcp_syn_retries define the number of retry connections for SYN and reduce the default parameters to control the number of SYN connections as little as possible.

Second, modify the syn configuration ulimit-HSn 65535 sysctl-w net.ipv4.tcp_max_syn_backlog=2048 sysctl-w net.ipv4.tcp_syncookies=1 sysctl-w net.ipv4.tcp_synack_retries=2 sysctl-w net.ipv4.tcp_syn_retries= 2, Add firewall rule # Syn flood attack (--limit 1 FORWARD s limit syn concurrency once per second) iptables-An INPUT-p tcp--syn-m limit-limit 1 ACCEPT # Anti-port scanning iptables-A FORWARD-p tcp--tcp-flags SYN ACK,FIN,RST RST-m limit-- limit 1Universe s-j ACCEPT # Flood prevention ping iptables-A FORWARD-p icmp--icmp-type echo-request-m limit-- limit 1Universe s-j ACCEPT 4, add boot boot and finally don't forget to write the commands in second, third and third parts to / etc/rc.d/rc.local

At this point, I believe you have a deeper understanding of "Linux how to defend against SYN attacks". You might as well do it in practice. Here is the website, more related content can enter the relevant channels to inquire, follow us, continue to learn!

Tags: Attack defense content function more times length queue learning configuration practical deeper interest parameter command practical practical simple operation method friend Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Docker Xiaomi Huawei Redmi NVidia