"DeCamp, Paul" <PDeCampat_private> writes: > Any assistance would be appreciated, and better yet, any advice as to where > on the Internet is a good location for looking up such obviously abnormal > activity and what possible explanations may be. Thanks. Could this be backscatter from someone else's SYN floods? That is, could these be packets being sent by a target machine in response to packets with a spoofed source address of your machine? The recent paper on using backscatter measurements for some statistical analysis of DOS attacks on the internet as a whole may be useful: http://www.caida.org/outreach/papers/backscatter/
This archive was generated by hypermail 2b30 : Fri May 25 2001 - 09:57:19 PDT