A security team is analyzing network traffic logs and observes a significant increase in connection attempts to a web server from a single source IP address, occurring rapidly over a short period. The connection attempts are incomplete, with the attacker sending only the initial SYN packet but never completing the three-way handshake. What type of Denial of Service (DoS) attack is this?
- AUDP Flood
- BSYN Flood
- CHTTP Flood
- DICMP Flood
Show answer & explanationAnswer & explanation
Correct answer: B. SYN Flood
A SYN flood is a type of DoS attack that exploits the TCP three-way handshake. The attacker sends a large number of SYN requests to a server but never completes the handshake by sending the final ACK. This leaves the server's connection tables full of half-open connections, exhausting resources and preventing legitimate users from connecting.
Why the other options are wrong
- A. UDP flood attacks overwhelm a target with UDP packets, which are connectionless, not incomplete TCP handshakes.
- C. HTTP flood attacks involve sending many legitimate-looking HTTP requests, not incomplete TCP handshakes.
- D. ICMP flood attacks overwhelm a target with ICMP echo requests (pings), not TCP connection attempts.
SYN Flood Attack
A type of Denial of Service (DoS) attack that exploits the TCP three-way handshake. The attacker sends a high volume of SYN requests to a target server but does not respond to the server's SYN-ACKs, leaving many half-open connections that exhaust the server's resources and prevent legitimate connections.
- Targets TCP services.
- Exploits the three-way handshake.
- Sends SYN, never ACK.
- Fills server's connection table (backlog).
Memory trick: SYN Flood is like knocking on a door and running away, over and over, until no one can get in.