SYN floods continue

> I don't know, but since nobody else seems to either, how about a
> router box that detects excessive SYN activity and then automatically
> blocks that ip address for awhile? I suppose it just means that
> the attacker has to vary the source address rapidly.
If they modulate the phasers we just need to modulate the sheilds. :open_mouth:

If someone comes up with a good solution we will be glad to impliment it.
Well, it's a good analogy (modulating the phasers).
But they're *randomizing* the phasers...