FINDING · EVALUATION

The user-level norm normalizer processes a realistic 100,000-packet trace (88% TCP) at approximately 101,000 pkts/sec (397 Mb/s) with all normalizations enabled on a $1,000 AMD Athlon 1.1 GHz PC, compared to a memory-copy-only baseline of 727,270 pkts/sec; the authors conclude a kernel implementation could sustain a bidirectional 100 Mbps access link with sufficient headroom to weather high-speed small-packet flooding attacks.

From 2001-handley-networkNetwork Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics · §7.2 · 2001 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpi

Extracted by claude-sonnet-4-6 — review before relying.