NOTE
1.10 SYN Attack
TCP half-open connections, SYN Flood detection, and defenses.
This is a historical learning note and may contain outdated or incomplete understanding.
1. TCP Half-Open Connections
During the three-way handshake, the state after the server sends SYN-ACK and before it receives the client’s ACK is called a half-open connection. A half-open connection also consumes system resources. If there are a large number of half-open connections, system resources can be exhausted and the service can no longer serve external requests.
A SYN attack takes advantage of this.
2. What Is a SYN Attack
In a short period of time, an attacker forges a large number of nonexistent IP addresses and continuously sends SYN packets to the server. The server sends SYN-ACK packets, but because the client IP addresses do not exist, the server has to wait for timeouts and retransmit. This causes a large number of half-open connections to occupy system resources.
3. How to Address It
3.1. Detection
There are a large number of half-open connections on the server and the IP addresses are random.
3.2. Defense
- Shorten the SYN timeout.
- Increase the maximum number of half-open connections.
- Use gateway filtering and protection.
- Use SYN cookies.
Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub