Browse > Article

The Extended TCP for Preventing from SYN Flood DoS Attacks  

Park Zin-Won (울산대학교 컴퓨터 정보통신공학부)
Kim Myung-Kyun (울산대학교 컴퓨터 정보통신공학부)
Abstract
The Denial of Service(DoS) attacks, which are done by consuming all of the computing or communication resources necessary for the services, are known very difficult to be protected from. TCP has drawbacks in its connection establishment for possible DoS attacks. TCP maintains the state of each partly established connection in the connection queue until it is established completely and accepted by the application. The attackers can make the queue full by sending connection requests repeatedly and not completing the connection establishment steps for those requests. In this paper, we have designed and implemented the extended TCP for preventing from SYN Flood DoS attacks. In the extended TCP, the state of each partly established connection is not maintained in the queue until the connection is established completely. For the extended TCP, we have modified the 3-way handshake procedure of TCP and implemented the extended TCP in the Linux operating system. The test result shows $0.05\%$ delay more than original TCP, but it shows that the extended TCP is strong for SYN Flood attacks.
Keywords
TCP; SYN Flood; DoS; Denial of Service; Security; Linux system;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Haining Wang: DanJu Zhang: Shin, K.G.:, 'SYN-dog: sniffing SYN flooding sources,' Distributed Computing Systems, 2002. Proceedings. 22nd International Conference on, 2-5 July 2002 Page(s): 421-428   DOI
2 Lau, F.; Rubin, S.H.; Smith, M.H.; Trajkovic, L.;, 'Distributed denial of service attacks,' Systems, Man, and Cybernetics, 2000 IEEE International Conference on, Volume: 3, 8-11 Oct. 2000 Page(s): 2275-2280 vol.3   DOI
3 Schuba, C.L.; Krsul, I.V.; Kuhn, M.G.; Spafford, E.H.; Sundaram, A.; Zamboni, D.;, 'Analysis of a denial of service attack on TCP,' Security and Privacy, 1997. Proceedings., 1997 IEEE Symposium on, 4-7 May 1997 Page(s): 208-223   DOI
4 Haining Wang: Danlu Zhang: Kang G. Shin., 'Detecting SYN flooding attacks,' INFOCOM 2002. Twenty-First Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings. IEEE, Volume: 3, 23-27 June 2002 Page(s): 1530-1539   DOI
5 Jonathan Lemon;, 'Resisting SYN flood DoS attacks with a SYN cache,' Proceedings of the BSDCon 2002 Conference, Feb 2002
6 Zin-Won Park; Joon-Hyung Lee; Myung-Kyung Kim;, 'Design of and Extended TCP for preventing DoS Attacks,' Proceedings of 2003KORUS, 2003, Page(s)385-389   DOI