Re: [tcpm] I-D ACTION:draft-ietf-tcpm-syn-flood-02.txt

Wesley Eddy <weddy@grc.nasa.gov> Fri, 09 March 2007 09:05 UTC

Return-path: <tcpm-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPb2W-0002S2-DH; Fri, 09 Mar 2007 04:05:28 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPQP5-0007tn-Nn for tcpm@ietf.org; Thu, 08 Mar 2007 16:44:03 -0500
Received: from mx1.grc.nasa.gov ([128.156.11.68]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPQP3-0005mK-Ab for tcpm@ietf.org; Thu, 08 Mar 2007 16:44:03 -0500
Received: from lombok-fi.grc.nasa.gov (seraph.grc.nasa.gov [128.156.10.10]) by mx1.grc.nasa.gov (Postfix) with ESMTP id 2D79EC2AD for <tcpm@ietf.org>; Thu, 8 Mar 2007 16:43:56 -0500 (EST)
Received: from apataki.grc.nasa.gov (apataki.grc.nasa.gov [139.88.112.35]) by lombok-fi.grc.nasa.gov (NASA GRC TCPD 8.13.7/8.13.7) with ESMTP id l28Lht40018322 for <tcpm@ietf.org>; Thu, 8 Mar 2007 16:43:55 -0500 (EST)
Received: from localhost (localhost [127.0.0.1]) by apataki.grc.nasa.gov (NASA GRC TCPD 8.13.7/8.13.7) with ESMTP id l28Lhtd6011078 for <tcpm@ietf.org>; Thu, 8 Mar 2007 16:43:55 -0500 (EST)
Received: from apataki.grc.nasa.gov ([127.0.0.1])by localhost (apataki.grc.nasa.gov [127.0.0.1]) (amavisd-new, port 10024)with ESMTP id E-ndW3d5YKJQ for <tcpm@ietf.org>; Thu, 8 Mar 2007 16:43:55 -0500 (EST)
Received: from drpepper.grc.nasa.gov (gr2134391.grc.nasa.gov [139.88.44.123])by apataki.grc.nasa.gov (NASA GRC TCPD 8.13.7/8.13.7) with ESMTP id l28Lhsrg011071for <tcpm@ietf.org>; Thu, 8 Mar 2007 16:43:54 -0500 (EST)
Received: by drpepper.grc.nasa.gov (Postfix, from userid 501)id 876CC4FE76; Thu, 8 Mar 2007 16:40:27 -0500 (EST)
Date: Thu, 08 Mar 2007 16:40:26 -0500
From: Wesley Eddy <weddy@grc.nasa.gov>
To: tcpm@ietf.org
Subject: Re: [tcpm] I-D ACTION:draft-ietf-tcpm-syn-flood-02.txt
Message-ID: <20070308214023.GE6361@grc.nasa.gov>
References: <E1HPPYo-0007FR-Nw@stiedprstage1.ietf.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <E1HPPYo-0007FR-Nw@stiedprstage1.ietf.org>
User-Agent: Mutt/1.5.5.1i
X-imss-version: 2.046
X-imss-result: Passed
X-imss-scores: Clean:99.90000 C:2 M:3 S:5 R:5
X-imss-settings: Baseline:1 C:1 M:1 S:1 R:1 (0.0000 0.0000)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 97adf591118a232206bdb5a27b217034
X-BeenThere: tcpm@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: weddy@grc.nasa.gov
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tcpm@ietf.org>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=subscribe>
Errors-To: tcpm-bounces@ietf.org

On Thu, Mar 08, 2007 at 03:50:02PM -0500, Internet-Drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts 
> directories.
> This draft is a work item of the TCP Maintenance and Minor Extensions Working Group of the IETF.
> 
> 	Title		: TCP SYN Flooding Attacks and Common Mitigations
> 	Author(s)	: W. Eddy
> 	Filename	: draft-ietf-tcpm-syn-flood-02.txt
> 	Pages		: 23
> 	Date		: 2007-3-8
> 	
> This document describes TCP SYN flooding attacks, which have been
>    well-known to the community for several years.  Various
>    countermeasures against these attacks, and the trade-offs of each,
>    are described.  This document archives explanations of the attack and
>    common defense techniques for the benefit of TCP implementers and
>    administrators of TCP servers or networks.
> 

This update includes a number of fairly minor grammatical tweaks and
wording clarifications suggested by Alfred Hoenes, Mark Allman, and Ted
Faber.  A paragraph on SYNs that carry data (e.g. as used in T/TCP) was
added with some measurment data showing how uncommon this is.  There
is a colorized diff online at:
http://tools.ietf.org/wg/tcpm/draft-ietf-tcpm-syn-flood/draft-ietf-tcpm-syn-flood-02-from-01.wdiff.html

I noticed that I need to fix the entry for [All07] in the references,
but that can be done after the WGLC that I think it's ready for since
all the diffs were quite minor and the reviews have been largely
positive.

-- 
Wesley M. Eddy
Verizon Federal Network Systems

_______________________________________________
tcpm mailing list
tcpm@ietf.org
https://www1.ietf.org/mailman/listinfo/tcpm