Hacker News new | past | comments | ask | show | jobs | submit login

> This allows for very fast dropping of DOS flood attacks.

OpenBSD has something very close to that w/ bpf(4) BIOCGFILDROP filter "drop".

https://man.openbsd.org/bpf#BIOCGFILDROP

https://man.openbsd.org/tcpdump#B

https://marc.info/?l=openbsd-tech&m=155228135415650&w=2




I think that's pretty different. It's less processing, but still copies packet off nic.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: