Syn flood attack – Allied Telesis AT-S63 User Manual
Page 164

Chapter 14: Denial of Service Defenses
164
Section II: Advanced Operations
SYN Flood Attack
In this type of attack, an attacker sends a large number of TCP connection 
requests (TCP SYN packets) with bogus source addresses to the victim. 
The victim responds with acknowledgements (SYN ACK packets), but 
because the original source addresses are bogus, the victim node does 
not receive any replies. If the attacker sends enough requests in a short 
enough period, the victim may freeze operations when the number of 
requests exceeds the capacity of its connections queue.
To defend against this form of attack, a switch port monitors the number of 
ingress TCP connection requests it receives. If a port receives more than 
60 requests per second, the following occurs.
The switch sends an SNMP trap to the management stations
The switch port is blocked for one minute.
This defense mechanism does not involve the switch’s CPU. You can 
activate it on some or all of the ports without impacting switch 
performance.
- AT-GS908M (54 pages)
- AT-x230-10GP (80 pages)
- AT-GS950/48PS (64 pages)
- AT-GS950/10PS (386 pages)
- AT-GS950/16PS (386 pages)
- AT-GS950/48PS (386 pages)
- AT-9000 Series (258 pages)
- AT-9000 Series (1480 pages)
- IE200 Series (70 pages)
- AT-GS950/48 (60 pages)
- AT-GS950/48 (410 pages)
- AT-GS950/8 (52 pages)
- AT-GS950/48 (378 pages)
- SwitchBlade x8106 (322 pages)
- SwitchBlade x8112 (322 pages)
- SwitchBlade x8106 (240 pages)
- SwitchBlade x8112 (240 pages)
- AT-TQ Series (172 pages)
- AlliedWare Plus Operating System Version 5.4.4C (x310-26FT,x310-26FP,x310-50FT,x310-50FP) (2220 pages)
- FS970M Series (106 pages)
- 8100L Series (116 pages)
- 8100S Series (140 pages)
- x310 Series (116 pages)
- x310 Series (120 pages)
- AT-GS950/24 (404 pages)
- AT-GS950/24 (366 pages)
- AT-GS950/16 (44 pages)
- AT-GS950/16 (404 pages)
- AT-GS950/16 (364 pages)
- AT-GS950/8 (364 pages)
- AT-GS950/8 (52 pages)
- AT-GS950/8 (404 pages)
- AT-8100 Series (330 pages)
- AT-8100 Series (1962 pages)
- AT-FS970M Series (330 pages)
- AT-FS970M Series (1938 pages)
- SwitchBlade x3112 (294 pages)
- SwitchBlade x3106 (288 pages)
- SwitchBlade x3106 (260 pages)
- SwitchBlade x3112 (222 pages)
- AT-S95 CLI (AT-8000GS Series) (397 pages)
- AT-S94 CLI (AT-8000S Series) (402 pages)
- AT-IMC1000T/SFP (23 pages)
- AT-IMC1000TP/SFP (24 pages)
- AT-SBx3106WMB (44 pages)
