The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

TCP full-connect attack

Prev Next

A TCP full-connect attack is an attack that has a valid source IP address and goes though the full TCP hand-shake process. The attacker uses real PCs with real IP addresses to generate a TCP full-connect attack. This is typically done using botnets. Sending TCP full-connect attacks from several botnets ties down server resources and creates a DoS condition. TCP full-connect usually is a DDoS attack launched from botnets in distributed systems.

A bot is defined as malicious software running on a compromised system that is designed to participate in a centrally managed network of compromised computers known as a botnet. Single botnets have been known to consist of over a million compromised computers, and are arguably the most significant threats to the global Internet today.

Multiple systems access a single Internet or service in a way that appears legitimate. This makes the detection of botnet-based DoS attacks difficult as it is hard to distinguish legitimate requests from those coming from a botnet. In the past, social networking site, Twitter is known to have experienced a DoS attack from a botnet.