ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A security analyst is reviewing network traffic logs and observes an unusually high volume of SYN packets originating from various external IP addresses targeting a specific server on the perimeter network, but very few corresponding SYN-ACKs are being sent back. What type of attack is most likely occurring?
- ACross-Site Scripting (XSS)
- BSYN Flood
- CSQL Injection
- DMan-in-the-Middle (MitM)
Show answer & explanationAnswer & explanation
Correct answer: B. SYN Flood
A SYN flood is a type of Denial-of-Service (DoS) attack where an attacker sends a high volume of SYN requests to a target server but never completes the three-way handshake, exhausting the server's resources and preventing legitimate connections.
Why the other options are wrong
- A. XSS is a client-side attack involving malicious scripts in web pages, not characterized by SYN packet anomalies.
- C. SQL injection targets database vulnerabilities and would not typically manifest as an unusual volume of SYN packets.
- D. MitM attacks involve intercepting communication between two parties and wouldn't primarily be identified by a high volume of unacknowledged SYN packets.
SYN Flood Attack
A type of Denial-of-Service (DoS) attack in which an attacker rapidly initiates a connection to a server without completing the three-way handshake, causing the server to exhaust its resources.
- Exploits the TCP three-way handshake.
- Sends many SYN packets but no final ACK.
- Overwhelms server's connection table, denying legitimate users.
Memory trick: SYN Flood is like a traffic jam at the server's entrance.