SYN flood

A denial-of-service attack that sends TCP connection requests and never completes the handshake, filling the target's queue of half-open connections so real clients are refused.

A SYN flood abuses the first step of the TCP three-way handshake. The attacker sends a stream of SYN segments; the server answers each with a SYN-ACK and reserves memory for the pending connection; the final ACK never arrives. Each half-open connection waits in the server’s backlog queue until it times out. Once the queue is full, legitimate users are refused even though the server is still running. Source addresses are commonly spoofed. RFC 4987 describes the attack and the usual mitigations.

It is a state-exhaustion attack rather than a pure bandwidth flood: the scarce resource is connection state, not link capacity, which is why a modest packet rate can be enough. The same pressure falls on any device that tracks connections, including a stateful inspection firewall. Mitigations include SYN cookies, which let the server avoid storing state until the handshake completes, larger backlogs with shorter timeouts, SYN proxying at a firewall or load balancer, and filtering upstream. Launched from many sources at once, it becomes a distributed denial-of-service attack.

Exam relevance: a scenario is likely to describe many half-open connections, or a server that stops accepting sessions under a burst of SYNs. Candidates are expected to name the attack, tie it to the handshake and to denial of service, and pick SYN cookies or filtering as the defence.