gpt4 book ai didi

linux - FreeBSD syncookies 机制

转载 作者:太空宇宙 更新时间:2023-11-04 11:46:26 30 4
gpt4 key购买 nike

我正在研究 FreeBSD TCP/IP 栈。似乎有 2 种 syn flood 机制,syncookies 和 syncache。我的问题是关于 syncookies,它是从头开始还是在 SYN 队列填满时开始?

最佳答案

manual page对于 syncache/syncookies 包含以下段落,这说明 syncookies 仅在先前的入口已从同步缓存中被逐出时才应用:

 Syncookies provides a way to virtually expand the size of the syncache by
keeping state regarding the initial SYN in the network. Enabling
syncookies sends a cryptographic value in the SYN,ACK reply to the client
machine, which is then returned in the client's ACK. If the correspond-
ing entry is not found in the syncache, but the value passes specific se-
curity checks, the connection will be accepted. This is only used if the
syncache is unable to handle the volume of incoming connections, and a
prior entry has been evicted from the cache.

关于linux - FreeBSD syncookies 机制,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/57531461/

30 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com