Re: ratelimiting/concurrency limits both inadequate to stop TCP/IP DoS

2001-03-02 Thread Pavel Kankovsky
On Wed, 28 Feb 2001, bert hubert wrote: I'm not certain weather its best to group ip addresses by /16 or /24 - /24 might consume too much memory, /16 might be too broad. Perhaps this should be a tunable parameter. IMHO the best approach would be to group them automatically. The addresses and

ratelimiting/concurrency limits both inadequate to stop TCP/IP DoS

2001-02-28 Thread bert hubert
On Tue, Feb 27, 2001 at 02:02:16AM +0100, Peter van Dijk wrote: inetd replacements like xinetd and tcpserver (http://cr.yp.to/ucspi-tcp.html) have real ratelimiting which preventes *real* problems, as opposed to inetd ratelimiting which actually only *creates* problems. This is not quite