Analysis of a denial of service attack on TCP

Christoph Schuba, Ivan Krsul, Markus Kühn, Eugene H. Spafford, Arvind Sundaram, Diego Zamboni

1997 · 484 citations · 2 references

Concepts

TL;DR

The paper analyzes a network‑based denial of service attack for IP networks, popularly called SYN flooding, where attackers send many TCP connection requests with spoofed source addresses, exhausting target host resources and denying legitimate access. The paper provides a detailed analysis of SYN flooding and discusses existing and proposed countermeasures. We introduce a new solution approach, explain its design, and evaluate its performance. Our approach protects all hosts on the same LAN, regardless of OS or networking stack, is highly portable, configurable, extensible, and requires no special hardware or router or end‑system modifications.

Abstract

The paper analyzes a network based denial of service attack for IP (Internet Protocol) based networks. It is popularly called SYN flooding. It works by an attacker sending many TCP (Transmission Control Protocol) connection requests with spoofed source addresses to a victim's machine. Each request causes the targeted host to instantiate data structures out of a limited pool of resources. Once the target host's resources are exhausted, no more incoming TCP connections can be established, thus denying further legitimate access. The paper contributes a detailed analysis of the SYN flooding attack and a discussion of existing and proposed countermeasures. Furthermore, we introduce a new solution approach, explain its design, and evaluate its performance. Our approach offers protection against SYN flooding for all hosts connected to the same local area network, independent of their operating system or networking stack implementation. It is highly portable, configurable, extensible, and requires neither special hardware, nor modifications in routers or protected end systems.

References

2