[dns-operations] How many kinds of DNS DoS attacks are we trying to stop ?

> I tested that while at CAIDA in order to qualify the sources of
> traffic hitting the root servers. Most of the OS fingerprinting is
> based on variations of the TCP handshake flags + other TCP elements.

Do note that this tool claims to be able to fingerprint sometimes with
only one packet:


But it's only TCP. The UDP header is really small and carries little

