Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: SYN Flood Attack

10/14/05

Permalink 11:58:17 pm, Categories: Information Security, 232 words   English (US)

SYN Flood Attack

One of the common types of denial of service attacks includes the SYN Flood Attack. Below is a short explanation on how this type of attack is perpretrated.

SYN Attack

Syn attack is another type of Denial of Service attack. This type of attack exploits the buffer space available between the client and server for exchanging messages. Thus, when a session is initiated between the Transmission Control Program (TCP) client and server in a network, a very small buffer space exists to handle the usually rapid 'handshaking' exchange of messages that set up the session. The session -establishing packets include a SYN field that identifies the sequence in the message exchange. The attacker exploits this by sending a number of connection requests very rapidly and then fails to respond to the reply. This attack leaves the first packet in the buffer so that other, legitimate connection requests can’t be accommodated. Although the packet in the buffer is dropped after a certain period of time without a reply, the effect of receiving many of these bogus connection requests is to make it difficult for legitimate requests for a session to get established. A SYN attack can be controlled by providing correct settings in the operating system, tuning the size of the buffer and the timeout period. This can be easily configured by the network administrator and can help prevent a SYN attack.

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

January 2009
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Misc

Syndicate this blog XML

What is RSS?