TCP SYN Flooding Attacks and Common Mitigations
RFC 4987, “TCP SYN Flooding Attacks and Common Mitigations”, is an Informational document published in August 2007 by W. Eddy. The canonical text is published by the RFC Editor.
Abstract
This document describes TCP SYN flooding attacks, which have been well-known to the community for several years. Various countermeasures against these attacks, and the trade-offs of each, are described. This document archives explanations of the attack and common defense techniques for the benefit of TCP implementers and administrators of TCP servers or networks, but does not make any standards-level recommendations. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 4987 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4986 Requirements Related to DNS Security Trust Anchor Rollover
- RFC 4988 Mobile IPv4 Fast Handovers
- RFC 4985 Internet X.509 Public Key Infrastructure Subject Alternative Name for Expression of Service Name
- RFC 4984 Report from the IAB Workshop on Routing and Addressing
- RFC 4990 Use of Addresses in Generalized Multiprotocol Label Switching Networks
- RFC 4983 Fibre Channel Registered State Change Notification MIB
- RFC 4991 A Common Schema for Internet Registry Information Service Transfer Protocols
- RFC 4982 Support for Multiple Hash Algorithms in Cryptographically Generated Addresses