Subject: Re: DOS attacks
To: Perry E. Metzger <perry@piermont.com>
From: Aaron J. Grier <agrier@poofygoof.com>
List: netbsd-advocacy
Date: 02/11/2000 12:01:48
On Fri, Feb 11, 2000 at 12:37:45PM -0500, Perry E. Metzger wrote:

> If you get attacked by a gig a second of bogus packets, NO system can
> help.

It sounds like the attacks are more dependent on routing
software/hardware than anything else.  I assume that if you spam a
NetBSD box with bogus traffic it won't simply keel over.  It's more a
connectivity issue than anything else.

http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-8&msg=20000211003101.A26181@securityfocus.com

the above has a summary.

So.. the question then becomes:  if we are using NetBSD as a router
upstream, could we use it to block these kinds of attacks?

-- 
  Aaron J. Grier | "Not your ordinary poofy goof." | agrier@poofygoof.com
  "Time Correct function allows automatically correcting slight variation
   of your key touching manner."  --  Roland MSQ-700 manual