11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

760 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresAFD.SYS ProtectionsThe following keys specify parameters for the kernel mode driver Afd.sys. Afd.sys isused to support Windows sockets applications. All of the keys <strong>and</strong> values in thissection are located under the registry keyHKLM\System\CurrentControlSet\Services\AFD\Parameters. These keys <strong>and</strong>values are:● Value: EnableDynamicBacklogRecommended value data: 1Valid values: 0 (disabled), 1 (enabled)Description: Specifies AFD.SYS functionality to withst<strong>and</strong> large numbers ofSYN_RCVD connections efficiently. For more information, see “Internet ServerUnavailable Because of Malicious SYN Attacks,” athttp://support.microsoft.com/default.aspx?scid=kb;en-us;142641.●●●Value name: MinimumDynamicBacklogRecommended value data: 20Valid values: 0–4294967295Description: Specifies the minimum number of free connections allowed on alistening endpoint. If the number of free connections drops below this value, athread is queued to create additional free connectionsValue name: MaximumDynamicBacklogRecommended value data: 20000Valid values: 0–4294967295Description: Specifies the maximum total amount of both free connections plusthose in the SYN_RCVD state.Value name: DynamicBacklogGrowthDeltaRecommended value data: 10Valid values: 0–4294967295Present by default: NoDescription: Specifies the number of free connections to create when additionalconnections are necessary.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!