Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 21, 2008, 07:42:41 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
184871
Posts
21465
Topics
52056
Members
Latest Member:
bibmo
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Frequently Asked Questions (FAQ) for Comodo firewall
"Do Packet Checksum Verification" - Should I Use It?
« previous
next »
Pages:
[
1
]
Author
Topic: "Do Packet Checksum Verification" - Should I Use It? (Read 3070 times)
Chuck
Comodo Member
Offline
Posts: 34
"Do Packet Checksum Verification" - Should I Use It?
«
on:
September 10, 2006, 09:34:30 PM »
I have a home-based, stand alone, direct connection to internet via modem on a WinXPSP-2 PC, using latest CPF (along with NOD32, TrojanHunter and HOSTS file for realtime protection). Just to see what would happen, I enabled "Do Packet Checksum Verification." My computer continues to run fine and I noticed that now I sometimes get dozens of high severity events logged during a session, not always, but sometimes. I find this intriguing and would like someone in the know to explain the significance of the access denials based upon checksum verification and if there is a reason why I shouldn't use it. Just curious. Thanks!
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 1721
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #1 on:
September 10, 2006, 10:08:05 PM »
Quote from: Chuck on September 10, 2006, 09:34:30 PM
I have a home-based, stand alone, direct connection to internet via modem on a WinXPSP-2 PC, using latest CPF (along with NOD32, TrojanHunter and HOSTS file for realtime protection). Just to see what would happen, I enabled "Do Packet Checksum Verification." My computer continues to run fine and I noticed that now I sometimes get dozens of high severity events logged during a session, not always, but sometimes. I find this intriguing and would like someone in the know to explain the significance of the access denials based upon checksum verification and if there is a reason why I shouldn't use it. Just curious. Thanks!
Some ethernet adapters calculates checksums in hardware for optimization. When this is a case, outgoing packets may be blocked because the checksum is not calculated yet. But if it is an incoming packet, then chsum verification is doing good.
A personal computer usually does not need such a verification as this verification is a defense against some DDOS attacks against server computers.
Hope this helps,
Egemen
Logged
Nikos
Comodo Loves me
Offline
Posts: 153
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #2 on:
September 11, 2006, 02:48:00 AM »
May i pop in plz and ask what exactly Packet CheckSum is and why it need verification?
Thank you.
Logged
svein
Comodo Member
Offline
Posts: 46
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #3 on:
September 11, 2006, 03:32:51 AM »
Ok, to simplify things:
A checksum is a mathematical way of controlling that the network packet is intact, and unmodified.
All (non-idiotic) network protocols include checksumming on layers 2 and 3. Most modern network adapters that do layer-3 decoding in the NIC, does the checksumming there, no need to worry.
The two reasons for enabling checksumming, would be:
a) to root out connectivity problems, i.e. packets that are damaged during transit from one host to another. The packet would simply be dropped (and thus seen as packetloss, and be retransmitted)
b) To be somewhat resistent to certain monkey-in-the-middle attacks, where a hostile machine between you and the remote host modifies data in the packet during transit, and thus inject "hostile" data.
If you are using a decent NIC, and are using good software, this shouldn't really be necessary to enable.
//Svein
Logged
Hi! I'm a .signature virus!
Copy me into your ~/.signature to help me spread!
panic
Global Moderator
Comodo's Hero
Online
Posts: 5314
... and I say to myself, "What a wonderful world"
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #4 on:
September 11, 2006, 04:41:25 AM »
Quote from: svein on September 11, 2006, 03:32:51 AM
Ok, to simplify things:
A checksum is a mathematical way of controlling that the network packet is intact, and unmodified.
All (non-idiotic) network protocols include checksumming on layers 2 and 3. Most modern network adapters that do layer-3 decoding in the NIC, does the checksumming there, no need to worry.
The two reasons for enabling checksumming, would be:
a) to root out connectivity problems, i.e. packets that are damaged during transit from one host to another. The packet would simply be dropped (and thus seen as packetloss, and be retransmitted)
b) To be somewhat resistent to certain monkey-in-the-middle attacks, where a hostile machine between you and the remote host modifies data in the packet during transit, and thus inject "hostile" data.
If you are using a decent NIC, and are using good software, this shouldn't really be necessary to enable.
//Svein
Hey Svein,
EXCELLENT answer mate. Very clear, very concise and very comprehensible. Well done.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Chuck
Comodo Member
Offline
Posts: 34
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #5 on:
September 11, 2006, 05:51:49 AM »
Thank you all for your responses.
Logged
Paulo
Comodo's Hero
Offline
Posts: 391
Re: "Do Packet Checksum Verification" - Should I Use It?
«
Reply #6 on:
September 11, 2006, 09:29:34 AM »
(Added to FAQ.)
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in -0.285 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com