NOTE

1.10 SYN Attack

TCP half-open connections, SYN Flood detection, and defenses.

SecurityCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. TCP Half-Open Connections

During the three-way handshake, the state after the server sends SYN-ACK and before it receives the client’s ACK is called a half-open connection. A half-open connection also consumes system resources. If there are a large number of half-open connections, system resources can be exhausted and the service can no longer serve external requests.

A SYN attack takes advantage of this.

2. What Is a SYN Attack

In a short period of time, an attacker forges a large number of nonexistent IP addresses and continuously sends SYN packets to the server. The server sends SYN-ACK packets, but because the client IP addresses do not exist, the server has to wait for timeouts and retransmit. This causes a large number of half-open connections to occupy system resources.

3. How to Address It

3.1. Detection

There are a large number of half-open connections on the server and the IP addresses are random.

3.2. Defense

  • Shorten the SYN timeout.
  • Increase the maximum number of half-open connections.
  • Use gateway filtering and protection.
  • Use SYN cookies.

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub