First International Conference on Innovative Computing, Information and Control - Volume I (ICICIC'06)
A Detective Method for SYN Flood Attacks
Beijing, China
August 30-September 01
ISBN: 0-7695-2616-0
DoS(Denial of Service) attacks are easily performed by utilizing the weakness of the network protocol. If should be notable that the firewall host hardly filters the SYN flood attacks, and the spoofed IP address keeps the position of the attacker from being traced. Early detection of this SYN flood attacks as well as the mechanism of escaping from the half-open state on TCP is requierd. In this paper, we present a detective method for SYN flood attacks in early stage. We implemented a prpgram to send the SYN packet and collected the SYN+ACK response packet from the server. Our method firstly built a standard model generated by observations for the activity of the server. Secondly, we detect the slight fluctuations in relation to the packet response rate and the average response delay. Finally, the RST packet is sent to the server on which half-open state on TCP is released.
Index Terms:
SYN Flood, Attack, DoS, Detective Method
Citation:
Takuo Nakashima, Shunsuke Oshima, "A Detective Method for SYN Flood Attacks," icicic, vol. 1, pp.48-51, First International Conference on Innovative Computing, Information and Control - Volume I (ICICIC'06), 2006