DocumentCode
3213721
Title
Analysis of a denial of service attack on TCP
Author
Schuba, Christoph L. ; Krsul, Ivan V. ; Kuhn, Markus G. ; Spafford, Eugene H. ; Sundaram, Aurobindo ; Zamboni, Diego
Author_Institution
Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
fYear
1997
fDate
4-7 May 1997
Firstpage
208
Lastpage
223
Abstract
The paper analyzes a network based denial of service attack for IP (Internet Protocol) based networks. It is popularly called SYN flooding. It works by an attacker sending many TCP (Transmission Control Protocol) connection requests with spoofed source addresses to a victim´s machine. Each request causes the targeted host to instantiate data structures out of a limited pool of resources. Once the target host´s resources are exhausted, no more incoming TCP connections can be established, thus denying further legitimate access. The paper contributes a detailed analysis of the SYN flooding attack and a discussion of existing and proposed countermeasures. Furthermore, we introduce a new solution approach, explain its design, and evaluate its performance. Our approach offers protection against SYN flooding for all hosts connected to the same local area network, independent of their operating system or networking stack implementation. It is highly portable, configurable, extensible, and requires neither special hardware, nor modifications in routers or protected end systems
Keywords
Internet; computer crime; data structures; transport protocols; Internet Protocol based networks; SYN flooding; TCP connections; Transmission Control Protocol; data structures; local area network; network based denial of service attack; networking stack implementation; operating system; spoofed source addresses; Access protocols; Computer crime; Data structures; Floods; IP networks; Local area networks; Operating systems; Protection; TCPIP; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy, 1997. Proceedings., 1997 IEEE Symposium on
Conference_Location
Oakland, CA
ISSN
1081-6011
Print_ISBN
0-8186-7828-3
Type
conf
DOI
10.1109/SECPRI.1997.601338
Filename
601338
Link To Document