Detect and block TCP Copy, possible?

Started by pwb, March 11, 2025, 02:08:06 PM

Previous topic - Next topic
Is it possible to detect and block TCPCopy traffic?

As TCPCopy apparently only captures and replicates arbitrary IP traffic to divert somewhere else by just rewriting address information with no application-specific encapsulation, there is obviously nothing that would make this diverted traffic identifiable or discernible from direct traffic hitting the target.
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 800 up, Bufferbloat A+