Table 319 Tcp Syn Flooding

Attack name

TCP SYN flooding

Class/subclass

Flood

Sample implementations

Apsend Spastic

Prerequisites

Direct access

Pertinent vulnerability

Software

Typical use

Overwhelm a specific host with connection requests

Attack result

Denial of service

Likely follow-up attack

Spoofs and rogue device

OSI layers

4

Detection

IDS, log analysis, and application security

Protection

TCP SYN cookies TCP intercept

Detection difficulty

3

Ease of use

5

Frequency

3

Impact

2

Overall rating

30

TCP SYN flood attacks are one of the earliest forms of flooding attacks. Kevin Mitnick used a form of TCP SYN flooding in his famous attack against Tsutomu Shimomura's computers. The attack works by sending a TCP SYN packet (the first packet of the TCP three-way handshake) and then never acknowledging the SYN-ACK that is sent in response. Because TCP is somewhat reliable, the server that received the SYN packet continues to keep the connection open for a configurable time period in case the SYN-ACK is eventually acknowledged. The server also periodically resends the SYN-ACK packet up to four times by default before tearing down the connection.

When attackers launch TCP SYN flood attacks, they send thousands of connection requests to a system in the hopes of consuming all of a server's available memory. This sometimes crashes the box or renders it useless. In the beginning, SYN floods were very easy to perform because the connection queue on systems was very small. In Kevin Mitnick's attack, he needed to launch only eight TCP SYN requests to fill the queue on one of Shimomura's computers.

Today, systems are more resilient to TCP SYN floods, in part because of improvements to the applications and operating systems, but also because of the deployment of technologies including TCP SYN cookies and TCP intercept. For more on these technologies, see the "DoS Design Considerations" section of Chapter 6.

NOTE

You may notice the absence of a UDP flooding attack in this discussion. This is intentional. Because UDP has no notion of connection, there is little further damage a UDP flood can do over a basic network flood at the IP layer. Also, many of the DDoS tools mentioned in the previous section are capable of using UDP as their means of flooding.

Continue reading here: Viruses Worms and Trojan Horses

Was this article helpful?

0 0