DocumentCode
476044
Title
Defending against tcp syn flooding with a new kind of syn-agent
Author
Liu, Pi-e ; Shen, Zhong-hua
Author_Institution
Sch. of Comput. Sci. & Technol., Harbin Univ. of Sci. & Technol., Harbin
Volume
2
fYear
2008
fDate
12-15 July 2008
Firstpage
1218
Lastpage
1221
Abstract
TCP-based flooding attack is a common form of denial-of-service (DoS) attacks which abuses network resources and may bring serious threats to the network. The SYN flood attack is a DoS method affecting hosts to retain the half-open state and exhaust its memory resources. This attack is hard to be filtered by the routers in case that the source IP address is always spoofed. There are some common ways to defend against this attach, but all of them either requires a high-performance firewall or trade time for space. In this paper, we proposed a method to build a new kind of syn-agent which uses the TCP header reserved flag bits to notify the server a complete three-way TCP handshake. First the syn-agent instead of the real server answer the client with ACK after received a SYN packet from the client. Then if it is a syn-attack, there should be no further ACKs after this. After a given short period, the half-open TCP sock should be deleted from the agent. If it is a really connection request, after the third time handshake packet arrived, the agent set the reserved bit in the TCP header to be dasia1psila and route the packet to the real server. When the server received a packet with the reserved bits set to be dasia1psila, it directly allocates memory for the connection and begins to communicate.
Keywords
IP networks; software agents; telecommunication network routing; telecommunication security; transport protocols; IP address; SYN-agent; TCP syn flooding attack; denial-of-service attacks; high-performance firewall; Computer crime; Computer science; Cybernetics; Electronic mail; Floods; Internet; Machine learning; TCPIP; Transport protocols; Web server; DoS; SYN flooding; syn-agent;
fLanguage
English
Publisher
ieee
Conference_Titel
Machine Learning and Cybernetics, 2008 International Conference on
Conference_Location
Kunming
Print_ISBN
978-1-4244-2095-7
Electronic_ISBN
978-1-4244-2096-4
Type
conf
DOI
10.1109/ICMLC.2008.4620589
Filename
4620589
Link To Document