• DocumentCode
    3213721
  • Title

    Analysis of a denial of service attack on TCP

  • Author

    Schuba, Christoph L. ; Krsul, Ivan V. ; Kuhn, Markus G. ; Spafford, Eugene H. ; Sundaram, Aurobindo ; Zamboni, Diego

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
  • fYear
    1997
  • fDate
    4-7 May 1997
  • Firstpage
    208
  • Lastpage
    223
  • Abstract
    The paper analyzes a network based denial of service attack for IP (Internet Protocol) based networks. It is popularly called SYN flooding. It works by an attacker sending many TCP (Transmission Control Protocol) connection requests with spoofed source addresses to a victim´s machine. Each request causes the targeted host to instantiate data structures out of a limited pool of resources. Once the target host´s resources are exhausted, no more incoming TCP connections can be established, thus denying further legitimate access. The paper contributes a detailed analysis of the SYN flooding attack and a discussion of existing and proposed countermeasures. Furthermore, we introduce a new solution approach, explain its design, and evaluate its performance. Our approach offers protection against SYN flooding for all hosts connected to the same local area network, independent of their operating system or networking stack implementation. It is highly portable, configurable, extensible, and requires neither special hardware, nor modifications in routers or protected end systems
  • Keywords
    Internet; computer crime; data structures; transport protocols; Internet Protocol based networks; SYN flooding; TCP connections; Transmission Control Protocol; data structures; local area network; network based denial of service attack; networking stack implementation; operating system; spoofed source addresses; Access protocols; Computer crime; Data structures; Floods; IP networks; Local area networks; Operating systems; Protection; TCPIP; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1997. Proceedings., 1997 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-8186-7828-3
  • Type

    conf

  • DOI
    10.1109/SECPRI.1997.601338
  • Filename
    601338