Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security analyst is reviewing network traffic logs and observes a high volume of TCP SYN packets originating from a single external IP address directed towards multiple internal hosts on various ports. There are very few corresponding SYN-ACK or ACK packets. What type of attack is most likely occurring?
- ASQL Injection
- BSYN Flood
- CMan-in-the-Middle (MitM)
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. SYN Flood
A SYN flood attack exploits the TCP three-way handshake by sending a large number of SYN requests without completing the handshake, thereby exhausting server resources. The observed traffic pattern of many SYN packets and few SYN-ACKs is characteristic of this attack.
Why the other options are wrong
- A. SQL injection targets databases via web application input, not typically identified by raw TCP SYN packet counts.
- C. MitM attacks involve intercepting communication between two parties, which does not primarily manifest as an abundance of unacknowledged SYN packets.
- D. XSS is a client-side code injection attack, not directly indicated by network-level SYN packet anomalies.
SYN Flood Attack
A type of Distributed Denial of Service (DDoS) attack that exploits the TCP three-way handshake by sending a flood of SYN requests to a server.
- Attacker sends SYN packets but doesn't complete the handshake.
- Server's connection table fills up, becoming unresponsive to legitimate requests.
- Commonly mitigated with SYN cookies or firewall rules.
Memory trick: Many SYN, no ACK, server's stack is under attack!