找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 2040|回复: 2

[其它] PSD参数的意义

[复制链接]
发表于 2006-7-19 10:59:20 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?注册

×
能给讲讲PSD参数的意义吗?····不明白其意义,也不会应用·······
routeros
发表于 2007-5-9 14:18:57 | 显示全部楼层
我也想了解,有知道的朋友请说明一下,谢谢
routeros
回复

使用道具 举报

发表于 2007-5-9 17:27:11 | 显示全部楼层
1. in ROS took this command from the demo2.mt.lv:

add chain=input protocol=tcp psd=21,3s,3,1 action=drop comment="detect and drop port scan connections" disabled=no



2. For English

From Netfilter.org:

3.12 psd patch
This patch by Dennis Koslowski adds a new match that will attempt to detect port scans.
In its simplest form, psd match can be used as follows :


# iptables -A INPUT -m psd -j DROP

# iptables --list
Chain INPUT (policy ACCEPT)
target prot opt source destination
DROP all -- anywhere anywhere psd weight-threshold: 21 delay-threshold: 300 lo-ports-weight: 3 hi-ports-weight: 1

Supported options for psd match are :

[--psd-weight-threshold threshold]

-> Portscan detection weight threshold
[--psd-delay-threshold delay]

-> Portscan detection delay threshold
[--psd-lo-ports-weight lo]

-> Privileged ports weight
[--psd-hi-ports-weight hi]

-> High ports weight
[--psd-hi-ports-weight hi]


Values here appear as the MT documentation with the exception of Delay Threshold which is 300 here and 3s in the MT documentation.
I'd suggest a review of the web documentation for IPTABLES and PSD for more information.




3. For chinese
  CONFIG_IP_NF_MATCH_PSD, 支持端口扫描检测(PSDortScanDetection). 可以检测TCP和UDP端口扫描. 它源自Solar Designer磗 scanlogd.

  支持的选项:

  --psd-weight-threshold

  从同一主机发往不同目的端口的TCP/UDP包的总的优先级,被用来作为端口扫描次序

  --psd-delay-threshold

  由同一主机发往不同目的端口的包的延迟 (in hundredths of second) ,用来作为可能的端口扫描子次序

  --psd-lo-ports-weight

  特权目的端口的优先级,即目标端口(<=1024)的优先级

  --psd-hi-ports-weight

  非特权目的端口的优先级(>1024).

  举例:iptables -A INPUT -m psd -j DROP

  CONFIG_IP_NF_MATCH_RPC,支持两个模块ip_conntrack_rpc_udp和ip_conntrack_rpc_tcp (用来分别跟踪UDP和TCP的端口映射请求),在iptabIe 中添加record_rpc(用来匹配是否包的源地址已经发过端口映射请求,或者是一个新的发往端口映射的GET请求,以允许RPC过滤)
routeros
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

QQ|Archiver|手机版|小黑屋|软路由 ( 渝ICP备15001194号-1|渝公网安备 50011602500124号 )

GMT+8, 2024-11-17 14:20 , Processed in 0.045255 second(s), 4 queries , Gzip On, Redis On.

Powered by Discuz! X3.5 Licensed

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表