The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to counter SYN floods with SYN cookies

Prev Next

A SYN flood attack is a series of SYN packets from forged IP addresses targeted at a specific server. When a server is attacked in this manner, the SYN queue in the server fills and all new connection requests are dropped. The SYN cookie feature is a mechanism to counter SYN flood attacks. This feature is an adjunct to the existing statistical anomaly-based Denial of Service detection. In cases where a DoS attack is already underway and there is no time for learning a long-term profile, Trellix IPS provides the ability for the Sensor to proxy all inbound three-way handshakes.

With SYN cookies, whenever a new connection request arrives at a server, the server does not maintain any information about the connection request. Instead it sends back a SYN+ACK with an ISN uniquely generated using the information present in the incoming SYN packet and a secret key. If the connection request is from a legitimate host, the server gets back an ACK from the host.

The Sensor will support a configurable threshold for SYN arrival rate, above which the Sensor will begin using SYN cookies to avoid having to maintain state during the three-way handshake. The Manager provides an interface to the user to enable/disable the SYN cookie feature. It also provides user the ability to configure the threshold values for the SYN cookies.