Home > Ask the Networking Experts > Questions & Answers > What causes a TCP SYN-attack?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What causes a TCP SYN-attack?

Retired expert - Karl Triebes EXPERT RESPONSE FROM: Retired expert - Karl Triebes

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 18 November 2005
I have a server and an application that communicate via TCP. At times the server side stops updating the application fully. In other words, not all parameters of the application are updated. The only way to correct the problem at the moment is by resetting the server. I used a network analyzer to attempt to get to the bottom of the problem. Based on the captured trace and research, I believe the problem to be a TCP SYN-attack. My question is what causes a TCP SYN-attack and are the symptoms that I described consistent with this type of attack?

>
EXPERT RESPONSE
A TCP SYN-attack refers to a commonly-seen denial of service attack that may be perpetrated against a host to prevent it from handling connections. By way of explanation, TCP stands for Transmission Control Protocol and is the primary transport for most of the data on the Internet. In order to open a connection to a host on the internet using TCP, a "3-way handshake" takes place between the client and the server. The first part of this handshake involves the client sending a TCP "SYN" ("Synchronize") packet, which is then acknowledged by the server.

The problem is that servers generally either have a resource limit on the number of outstanding connections they can have in this handshake pending-completion state, and may refuse to service further connections until these resources are available. This corresponds to the symptoms you have described. Since the overhead with sending a SYN packet is small, even a client on a relatively low-bandwidth link may be able to launch a significantly damaging attack. The problem is further exacerbated by network providers who do not perform source address filtering, allowing the attacker to effectively hide their identities.

Common solutions involve using servers that are resilient to such attacks. Of course, this is often easier said than done, so the preferred method of protection for many sites generally involves deploying a traffic management device that can block such attacks from ever reaching their servers. When deploying such a device, one should evaluate that the device not only blocks these attacks, but does not impose any penalty to the overall user experience.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Configuration Management
How to achieve server virtualization in your network
Juniper updates Network and Security Manager to manage full portfolio
DNS management becoming critical to businesses but poorly understood
Virtual machines present dynamic environment issues for network pros
Network architecture and capacity planning for server virtualization
Network configuration management software boosts university networking
Virtualization and the network a hot topic at Interop
Server virtualization creates a network configuration burden
Server virtualization: FAQ for network pros
A basic virtualized enterprise -- from 'Network Virtualization'
Network Configuration Management Research

Network Monitoring
Networking data visualization not just for pointy-headed bosses
What network security threat does a QM FSM error pose in IPsec VPNs?
Juniper updates Network and Security Manager to manage full portfolio
Network management software vendors readying IPv6
DNS management becoming critical to businesses but poorly understood
SolarWinds adds enterprise scalability to its network monitoring tool
Network forensics appliance gets storage boost and 10 GbE support
Tracking NetFlow over MPLS helps airline with compliance
When it comes to data loss prevention, networking should be part of the conversation
Network management takes interface tips from gaming industry, Google
Network Monitoring Research

Network Performance
Next-generation enterprise networks: Links to telecom carriers grow stronger
Application acceleration cements concrete co.'s consolidation project
Streaming Olympics video will drain corporate bandwidth
College IT department transforms itself with network management tools
How to prioritize wireless traffic
WAAS accelerates collaboration, increases revenue at engineering firm
Network management frameworks: FCAPS and ITIL
Governance, compliance, security: How are these network problems?
Network pros spend months on troubleshooting
Open source network monitoring reaches for the enterprise

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DEN  (SearchNetworking.com)
device relationship management  (SearchNetworking.com)
inverse multiplexing over ATM  (SearchNetworking.com)
loose coupling  (SearchNetworking.com)
network configuration management  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts