Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SYN floods continue (fwd)
From: Geoff Mulligan <geoff @ mulligan . com>
Date: Wed, 11 Sep 1996 17:40:44 -0600
To: roberth @ cet . com
Cc: amolitor @ anubis . network . com, firewalls @ GreatCircle . COM
In-reply-to: Your message of "Wed, 11 Sep 1996 15:15:48 -0700 (PDT)"
References: <Pine . LNX . 3 . 94 . 960911151109 . 14960B-100000 @ cet . cet . com>

From: Robert Hanson <roberth @
 cet .
 com>
> logically speaking... isnt there some integral part of a syn flood or syn
> this or that that is "detectable" and therefor "blockable" or that it will
> allow some "logic" to be coded to prevent full scale "bombing"?

If the SYN flood is done "right", it is impossible to block AT THE
DESTINATION without blocking valid traffic because there is no way of
knowing what is a valid SYN segment from a flood SYN segment.  Only a
foolish person would send the SYN segments from their real IP address,
which could blocked and be traced back to the source.

It is possible to block this type of attack at the source, or at least
force the flooder to use their real IP address - the routers at leaf
networks would have to drop ip packets carrying source addresses not
known to be on the incomming interface - much like stopping inbound ip
spoofing. 

> in this syn function, what is so "necessary" about it that a machine must
> "answer" to it good or bad?

SYN segments are an integral part of the TCP 3-way handshake protocol
used to set up a TCP connection and therefore cannot be eliminated.

When a host receives a SYN segment it allocates some resources for the
incomming connection.  Most systems will allow 5 to 8 queued incomming
connections before dropping all further packets sent to that port.  Each
of these queued connections will remain in place for approximately 75
seconds before timing out.  Therefore by simply sending SYN segments
from random ip addresses at 10 intervals to a hosts www port the web
server would be blocked.

	geoff


References:
Indexed By Date Previous: [no subject]
From: Peiter Z <peiterz @ secnet . com>
Next: *STOP* sending unsubscription requests to the list
From: Aydin Edguer <edguer @ MorningStar . Com>
Indexed By Thread Previous: Re: SYN floods continue (fwd)
From: Ron DuFresne <dufresne @ winternet . com>
Next: Re: SYN floods continue (fwd)
From: "Paul D. Robertson" <proberts @ clark . net>

Google
 
Search Internet Search www.greatcircle.com