Seperate queues for pending and established connections.


Hi list,

I was doing a quick study on what/which OS-level defenses have evolved
since 1996 against SYN flood. I was wondering whether the two separate
queues implemented in Linux/Solaris/*BSD et al. for pending and
established connections has something to do with SYN flood defense. Some
popular books tend to imply that, but I failed to see how that helps.

Any explanations? Google surprisingly wasn't very helpful. 

Thanks and bye,