Preventing IP Spoofing Attack SYN Firewall Design and Implementation Based on Linux
FU Cun-jun · Science Technology and Engineering · 2013
The design is based on redhat5.0 experiment platform,its aim is to build a packet filtering firewall to defend IP spoofing SYN attack.Based on RED algorithm,combination of TCP packet retransmission mechanism,SYN packet IP address authenticity is inspected.Using the RED algorithm to determine the average queue length of TCP and packet dropping probability,average queue size exceeds the maximum value that the system can bear,directly according to the random assignment of the drop probability to judge whether discard packets.The average queue length in the system loading,if the current discard probability is greater than a given threshold,then check hash table have the same data node or not,found to accept the packet,not found preserved the information of data packet to a hash table,and discard the packet.After analysis and experimental verification this firewall has better throughput,while the normal data packet has higher rate.