Table 319 Tcp Syn Flooding
|
Attack name |
TCP SYN flooding |
|
Class/subclass |
Flood |
|
Sample implementations |
Apsend Spastic |
|
Prerequisites |
Direct access |
|
Pertinent vulnerability |
Software |
|
Typical use |
Overwhelm a specific host with connection requests |
|
Attack result |
Denial of service |
|
Likely follow-up attack |
Spoofs and rogue device |
|
OSI layers |
4 |
|
Detection |
IDS, log analysis, and application security |
|
Protection |
TCP SYN cookies TCP intercept |
|
Detection difficulty |
3 |
|
Ease of use |
5 |
|
Frequency |
3 |
|
Impact |
2 |
|
Overall rating |
30 |
TCP SYN flood attacks are one of the earliest forms of flooding attacks. Kevin Mitnick used a form of TCP SYN flooding in his famous attack against Tsutomu Shimomura's computers. The attack works by sending a TCP SYN packet (the first packet of the TCP three-way handshake) and then never acknowledging the SYN-ACK that is sent in response. Because TCP is somewhat reliable, the server that received the SYN packet continues to keep the connection open for a configurable time period in case the SYN-ACK is eventually acknowledged. The server also periodically resends the SYN-ACK packet up to four times by default before tearing down the connection.
When attackers launch TCP SYN flood attacks, they send thousands of connection requests to a system in the hopes of consuming all of a server's available memory. This sometimes crashes the box or renders it useless. In the beginning, SYN floods were very easy to perform because the connection queue on systems was very small. In Kevin Mitnick's attack, he needed to launch only eight TCP SYN requests to fill the queue on one of Shimomura's computers.
Today, systems are more resilient to TCP SYN floods, in part because of improvements to the applications and operating systems, but also because of the deployment of technologies including TCP SYN cookies and TCP intercept. For more on these technologies, see the "DoS Design Considerations" section of Chapter 6.
NOTE
You may notice the absence of a UDP flooding attack in this discussion. This is intentional. Because UDP has no notion of connection, there is little further damage a UDP flood can do over a basic network flood at the IP layer. Also, many of the DDoS tools mentioned in the previous section are capable of using UDP as their means of flooding.
Continue reading here: Viruses Worms and Trojan Horses
Was this article helpful?