loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
First International Conference on Innovative Computing, Information and Control - Volume I (ICICIC'06)
A Detective Method for SYN Flood Attacks
Beijing, China
August 30-September 01
ISBN: 0-7695-2616-0
Takuo Nakashima, Kyushu Tokai University, Japan
Shunsuke Oshima, Yatsushiro National College of Technology, Japan
DoS(Denial of Service) attacks are easily performed by utilizing the weakness of the network protocol. If should be notable that the firewall host hardly filters the SYN flood attacks, and the spoofed IP address keeps the position of the attacker from being traced. Early detection of this SYN flood attacks as well as the mechanism of escaping from the half-open state on TCP is requierd. In this paper, we present a detective method for SYN flood attacks in early stage. We implemented a prpgram to send the SYN packet and collected the SYN+ACK response packet from the server. Our method firstly built a standard model generated by observations for the activity of the server. Secondly, we detect the slight fluctuations in relation to the packet response rate and the average response delay. Finally, the RST packet is sent to the server on which half-open state on TCP is released.
Index Terms:
SYN Flood, Attack, DoS, Detective Method
Citation:
Takuo Nakashima, Shunsuke Oshima, "A Detective Method for SYN Flood Attacks," icicic, vol. 1, pp.48-51, First International Conference on Innovative Computing, Information and Control - Volume I (ICICIC'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.