CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is investigating a report of slow network performance and suspicious activity on a web server (10.10.10.10). The analyst captures the following network traffic summary during the incident: ``` Time Source IP Destination IP Protocol Length Info 0.000000 192.168.1.100 10.10.10.10 TCP 74 50000 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000050 192.168.1.101 10.10.10.10 TCP 74 50001 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000060 192.168.1.102 10.10.10.10 TCP 74 50002 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 ... 0.000100 192.168.1.103 10.10.10.10 TCP 74 50003 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 0.000110 192.168.1.104 10.10.10.10 TCP 74 50004 -> 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 ``` The web server is not responding to legitimate requests, and the analyst notes a large number of similar `[SYN]` packets from various source IPs to the web server's port 80, with very few corresponding `[SYN-ACK]` or `[ACK]` packets from the server. What type of attack is most likely occurring?

  1. ASYN Flood
  2. BUDP Flood
  3. CICMP Flood
  4. DHTTP Flood
Show answer & explanation

Correct answer: A. SYN Flood

A SYN flood is a type of Denial of Service (DoS) attack where an attacker sends a rapid succession of SYN requests to a target server's open ports, but either does not respond to the server's SYN-ACKs or uses spoofed source IP addresses. This leaves the server with many half-open connections, exhausting its connection table and preventing it from accepting legitimate connections. The log shows numerous `[SYN]` packets to port 80 from various sources, with no corresponding `[SYN-ACK]` or `[ACK]` from the server, which is the signature of a SYN flood.

Why the other options are wrong

  • B. A UDP flood would involve a high volume of UDP packets, not TCP SYN packets.
  • C. An ICMP flood would involve a high volume of ICMP echo requests (pings), not TCP SYN packets.
  • D. An HTTP flood would involve legitimate-looking HTTP GET/POST requests, not just SYN packets.

SYN Flood

A Denial of Service (DoS) attack that exploits the TCP three-way handshake by sending a high volume of SYN packets to a target server, but never completing the handshake, thus exhausting the server's connection resources.

  • Leaves many 'half-open' connections on the server.
  • Often uses spoofed source IP addresses.
  • Results in legitimate clients being unable to connect.

Memory trick: DoS attacks overwhelm systems with traffic.

More Security Operations questions