A SYN flood attack is a series of SYN packets from forged IP addresses targeted at a specific server. When a server is attacked in this manner, the SYN queue in the server fills and all new connection requests are dropped. The SYN cookie feature is a mechanism to counter SYN flood attacks. This feature is an adjunct to the existing statistical anomaly-based Denial of Service detection. In cases where a DoS attack is already underway and there is no time for learning a long-term profile, Trellix IPS provides the ability for the Sensor to proxy all inbound three-way handshakes.
With SYN cookies, whenever a new connection request arrives at a server, the server does not maintain any information about the connection request. Instead it sends back a SYN+ACK with an ISN uniquely generated using the information present in the incoming SYN packet and a secret key. If the connection request is from a legitimate host, the server gets back an ACK from the host.
The Sensor will support a configurable threshold for SYN arrival rate, above which the Sensor will begin using SYN cookies to avoid having to maintain state during the three-way handshake. The Manager provides an interface to the user to enable/disable the SYN cookie feature. It also provides user the ability to configure the threshold values for the SYN cookies.