What benefit is conferred by TCP timestamp?

后端 未结 5 2037
野趣味
野趣味 2020-12-22 23:54

I have a security scan finding directing me to disable TCP timestamps. I understand the reasons for the recommendation: the timestamp can be used to calculate server uptime,

5条回答
  •  谎友^
    谎友^ (楼主)
    2020-12-23 00:11

    I got asked a similar question on this topic, today. My take is as follows:

    An unpatched system is the vulnerability, not whether attacker(s) can easily find it. The solution, therefore, is to patch your systems regularly. Disabling TCP timestamps won't do anything to make your systems less vulnerable - it's simply security through obscurity, which is no security at all.

    Turning the question on its head, consider scripting a solution that uses TCP timestamps to identify hosts on your network that have the longest uptimes. These will typically be your most vulnerable systems. Use this information to prioritise patching, to ensure that your network remains protected.

    Don't forget that information like uptime can also be useful to your system administrators. :)

提交回复
热议问题