From: Michy Eika (cciemaster@shingor.net)
Date: Wed May 17 2006 - 11:33:48 ART
Hi folks
I wanna clarify TCP intercept fanctionality.
According to the section,"Changing the TCP Intercept Aggressive Thresholds",
the web site below,
in terms of "aggressive behavior begins and ends", written like below.
b"If in watch mode, the watch timeout is reduced by half. (If the default is
in place, the watch timeout becomes 15 seconds.)
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecu
r_c/ftrafwl/scfdenl.htm
So I wonder if we can know whether the SYN attack starts or not by measuring
how long half open-session is cut?
My opinion may be incorrect. Please correct me!
TIA
Michy
This archive was generated by hypermail 2.1.4 : Thu Jun 01 2006 - 06:33:21 ART