Detecting SYN Flooding Attacks
#1

Detecting SYN Flooding Attacks
Outline
Introduction
Related Issues
Attack Detection
Performance Evaluation
Future Work
Conclusion
Introduction
Attacks on popular sites
Most of them are DoS using TCP
SYN Flooding exploits TCP 3-way hand-shake
Syn Cache, Syn cookies, SynDefender, Syn Proxying and SynKill
Installed on firewall or victim server
Introduction (cont)
Specialized firewalls become worthless with 14000 packets per sec.
FDS – Flooding Detection System
Installed on leaf routers (First-mile or Last-mile routers)
FDS uses key feature of TCP SYN-FIN pairs behavior.
Introduction (cont)
TCP packet classification is done at leaf router
SYN (beginning) FIN (END) for each TCP connection
No means to distinguish active FIN and passive FIN
RST violates the SYN-FIN pairs
Three new variables introduced to count SYN,FIN, and RST
Related Issues
Packet Classification
Placement of Detection Mechanism
Discrepancy between SYN’s and FIN’s
Packet classification
Packet Classification is done at the leaf router
First two steps confirm that it is a TCP packet
Code Bits in IP packet equals the sum of the length of IP header and offset of code BIT’s in TCP
Placement of Detection Mechanism
FDS is installed at the first-mile and last mile router
First-mile is more likely to catch flooding detection due to proximity to sources.
Last-mile quickly detects the flooding but cant provide hint about flooding sources
FDS is not installed at core due to a) it is close to neither flooding sources not the victim b) packets of the same flow could traverse different paths
Discrepancy btw SYN’s and FIN’s
Single RST packet can terminate a TCP session
Passive RST transmitted in response to close the port
Active RST transmitted in response to abort a TCP connection and associated with a SYN
Normal behavior of TCPSadSYN,FIN), (SYN/ACK,FIN) and (SYN,RSTactive)
FDS cannot differentiate between active and passive RST
Reply

Important Note..!

If you are not satisfied with above reply ,..Please

ASK HERE

So that we will collect data for you and will made reply to the request....OR try below "QUICK REPLY" box to add a reply to this page
Popular Searches: dfd for efficient flooding scheme, capteur de fin, data flooding attacks ppt, ppt data flooding attack in mobile adhoc network, lazy flooding a new technique for information dissemination in distributed network, firecol a collaborative protection network for the detection of flooding ddos attacks ppt, flooding drains in trivandrum,

[-]
Quick Reply
Message
Type your reply to this message here.

Image Verification
Please enter the text contained within the image into the text box below it. This process is used to prevent automated spam bots.
Image Verification
(case insensitive)

Possibly Related Threads...
Thread Author Replies Views Last Post
  Sniffer for Detecting Lost Mobiles project uploader 1 1,206 30-11-2012, 12:56 PM
Last Post: seminar details
  Traceback of DDoS Attacks using Entropy Variations seminar details 0 820 09-06-2012, 05:37 PM
Last Post: seminar details
  Detecting Wide Lines Using Isotropic Nonlinear Filtering seminar paper 0 647 14-03-2012, 04:02 PM
Last Post: seminar paper
  BUFFER OVERFLOW ATTACKS seminar addict 1 856 05-03-2012, 12:02 PM
Last Post: seminar paper
  Secure Routing in Wireless Sensor Networks:Attacks and Countermeasures seminar addict 1 1,429 16-02-2012, 04:06 PM
Last Post: seminar paper
  Detecting and Locating Wormhole Attacks in Wireless Ad Hoc Networks seminar paper 0 722 09-02-2012, 12:57 PM
Last Post: seminar paper
  HAMMING CODE GENERATION AND ERROR DETECTING AND CORRECTING seminar addict 0 1,147 30-01-2012, 03:48 PM
Last Post: seminar addict
  Fast Detection of Mobile Replica Node Attacks in Wireless Sensor Networks seminar addict 0 898 20-01-2012, 11:20 AM
Last Post: seminar addict
  DETECTING POWER GRID SYNCHRONIZATION FAILURE seminar addict 0 1,819 18-01-2012, 12:54 PM
Last Post: seminar addict
  Detecting Patient Motion in SPECT Imaging Using Stereo Optical Cameras seminar addict 0 688 17-01-2012, 11:10 AM
Last Post: seminar addict

Forum Jump: