alert icmp any any -> any any (msg:"ICMP Packet Detected"; sid:1000002;)https://daengsik.tistory.com/m/51
https://systemanswer.tistory.com/entry/Network-Routing-Protocol-%EB%B9%84%EA%B5%90-IGP-EGP
ifconfig eth0 promiscifconfig eth0 -promiscarp -s ip주소 mac주소10.10.10.0/24sysctl -w net.ipv4.tcp_syncookies=1echo 1 > /proc/sys/net/ipv4/tcp_syncookies0: 미설정, 1: 설정TCP SYN Flooding: Backlog Queue를 가득 채워 연결 자원을 소진시키는 DoS 공격
sysctl -w net.ipv4.tcp_max_syn_backlog=1024임계치 기반 차단 (pps 설정): iptables -A INPUT -p tcp --syn --dport 80 -m connlimit --connlimit-above 30 -j DROP
sysctl -w net.ipv4.tcp_syncookies=1sysctl -aIpSecsysctl -n parametersysctl -w parameter=valuendddirected-broadcastsmurf attack 커널 파라미터 대응Solaris: backlog queue resizendd -set /dev/tcp tcp_conn_req_max_q0 1024Linux: backlog queue resizesysctl -w net.ipv4.tcp_max_syn_backlog=1024Linux: TCP SYN Cookies 설정sysctl -w net.ipv4.tcp_syncookies=1ICMP Redirect 커널 레벨 대응ip source routing 대응ip forward 비활성화무선랜 보안설정wpa3무선 AP mac address filteringVPN 프로토콜ipsecno ip unreachablesnull routingconnection, socket timeoutno ip source-routecisco route 기능snmp-server community 123 ro 100no snmp-serverwildcard maskline vty 0tcp closeipconfig eth0 -promisc