• DocumentCode
    476044
  • Title

    Defending against tcp syn flooding with a new kind of syn-agent

  • Author

    Liu, Pi-e ; Shen, Zhong-hua

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Harbin Univ. of Sci. & Technol., Harbin
  • Volume
    2
  • fYear
    2008
  • fDate
    12-15 July 2008
  • Firstpage
    1218
  • Lastpage
    1221
  • Abstract
    TCP-based flooding attack is a common form of denial-of-service (DoS) attacks which abuses network resources and may bring serious threats to the network. The SYN flood attack is a DoS method affecting hosts to retain the half-open state and exhaust its memory resources. This attack is hard to be filtered by the routers in case that the source IP address is always spoofed. There are some common ways to defend against this attach, but all of them either requires a high-performance firewall or trade time for space. In this paper, we proposed a method to build a new kind of syn-agent which uses the TCP header reserved flag bits to notify the server a complete three-way TCP handshake. First the syn-agent instead of the real server answer the client with ACK after received a SYN packet from the client. Then if it is a syn-attack, there should be no further ACKs after this. After a given short period, the half-open TCP sock should be deleted from the agent. If it is a really connection request, after the third time handshake packet arrived, the agent set the reserved bit in the TCP header to be dasia1psila and route the packet to the real server. When the server received a packet with the reserved bits set to be dasia1psila, it directly allocates memory for the connection and begins to communicate.
  • Keywords
    IP networks; software agents; telecommunication network routing; telecommunication security; transport protocols; IP address; SYN-agent; TCP syn flooding attack; denial-of-service attacks; high-performance firewall; Computer crime; Computer science; Cybernetics; Electronic mail; Floods; Internet; Machine learning; TCPIP; Transport protocols; Web server; DoS; SYN flooding; syn-agent;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Machine Learning and Cybernetics, 2008 International Conference on
  • Conference_Location
    Kunming
  • Print_ISBN
    978-1-4244-2095-7
  • Electronic_ISBN
    978-1-4244-2096-4
  • Type

    conf

  • DOI
    10.1109/ICMLC.2008.4620589
  • Filename
    4620589