Packet analysis using packet filtering and traffic monitoring techniques

S.H.C. Haris, R. Badlishah Ahmad, Mohd Alif Hasmani Abd Ghani, Ghossoon M. Waleed · 2010

Malicious attackers intended to annihilate the availability of network server with threats such as Transmission Control Protocol (TCP) Synchronized (SYN) Flood. The attackers usually make the server exhausted and unavailable in order to complete the TCP three-way handshake mechanism. Detecting TCP SYN Flood in the Hypertext Transfer Protocol (HTTP) is the main problem in this paper. Anomaly detection is used to detect TCP SYN flood attack focusing in payload and unusable area. The unusual three-way handshake mechanism is also being analyzed. The results show that the proposed detection method using the combination of packet filtering and traffic monitoring can detect TCP SYN Flood in the network.

Read the paper · More papers on PaperTik