DocumentCode :
476044
Title :
Defending against tcp syn flooding with a new kind of syn-agent
Author :
Liu, Pi-e ; Shen, Zhong-hua
Author_Institution :
Sch. of Comput. Sci. & Technol., Harbin Univ. of Sci. & Technol., Harbin
Volume :
2
fYear :
2008
fDate :
12-15 July 2008
Firstpage :
1218
Lastpage :
1221
Abstract :
TCP-based flooding attack is a common form of denial-of-service (DoS) attacks which abuses network resources and may bring serious threats to the network. The SYN flood attack is a DoS method affecting hosts to retain the half-open state and exhaust its memory resources. This attack is hard to be filtered by the routers in case that the source IP address is always spoofed. There are some common ways to defend against this attach, but all of them either requires a high-performance firewall or trade time for space. In this paper, we proposed a method to build a new kind of syn-agent which uses the TCP header reserved flag bits to notify the server a complete three-way TCP handshake. First the syn-agent instead of the real server answer the client with ACK after received a SYN packet from the client. Then if it is a syn-attack, there should be no further ACKs after this. After a given short period, the half-open TCP sock should be deleted from the agent. If it is a really connection request, after the third time handshake packet arrived, the agent set the reserved bit in the TCP header to be dasia1psila and route the packet to the real server. When the server received a packet with the reserved bits set to be dasia1psila, it directly allocates memory for the connection and begins to communicate.
Keywords :
IP networks; software agents; telecommunication network routing; telecommunication security; transport protocols; IP address; SYN-agent; TCP syn flooding attack; denial-of-service attacks; high-performance firewall; Computer crime; Computer science; Cybernetics; Electronic mail; Floods; Internet; Machine learning; TCPIP; Transport protocols; Web server; DoS; SYN flooding; syn-agent;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Machine Learning and Cybernetics, 2008 International Conference on
Conference_Location :
Kunming
Print_ISBN :
978-1-4244-2095-7
Electronic_ISBN :
978-1-4244-2096-4
Type :
conf
DOI :
10.1109/ICMLC.2008.4620589
Filename :
4620589
Link To Document :
بازگشت