Three-way handshake

The SYN, SYN-ACK and ACK exchange that opens a TCP connection, in which each side confirms the other can be reached and the two agree their starting sequence numbers.

The three-way handshake is how TCP opens a connection, as defined in RFC 9293, the current TCP specification. The client sends a SYN segment carrying its initial sequence number. The server replies with a segment that has both the SYN and ACK flags set, acknowledging the client’s number and offering its own. The client returns an ACK for the server’s number, and data can then flow both ways. Each side now knows where the other’s byte count starts. Closing is a separate exchange of FIN and ACK segments, and an RST segment aborts a connection at once.

Several attacks work by bending this exchange. A SYN flood sends the first step and abandons the rest, leaving the server holding half-open connections. A half-open port scan sends a SYN and reads the reply to learn whether a port is open, without finishing the connection. TCP-level session hijacking depends on predicting or observing sequence numbers, which is why initial sequence numbers are meant to be unpredictable. UDP has no handshake, which is one reason a request with a forged source address can still draw a reply.

Exam relevance: a scenario may give the three flags in order and ask what is happening, or describe connections that stall after the SYN-ACK. Candidates are expected to know the sequence and to connect its abuse to SYN floods and scanning.