A TCP RST attack takes place when the attacker sends a large volume of malicious, mimicked TCP RST packets aimed to prematurely terminate active TCP sessions.
In TCP RST attacks, the network is constantly monitored for TCP connection requests sent to the victim. As soon as such a request is found, the attacker sends a spoofed TCP reset packet to the victim and obliges it to terminate the TCP connection.
Consider the following example. Computer A crashes while a TCP connection is in progress. Ccomputer B, on the other end, interacting with computer A continues to send TCP packets since it does not know computer A has crashed. When computer A restarts, it receives packets from the pre-crash connection. Computer A has no context for these packets and sends a TCP reset to computer B. This reset lets computer B know that the connection is no longer working. The user on computer B tries another connection. However, a third computer or computers (DoS attackers) monitoring the TCP packets on the connection, might send premature forged or mimicked TCP reset packets to one or both endpoints to terminate active TCP connections.
This attack consumes system resources that receive, check, and discard the packets, thus causing a DoS condition.