Eccouncil 312-50 Exam - Topic 16 Question 102 Discussion
Your network infrastructure is under a SYN flood attack. The attacker has crafted an automated botnet tosimultaneously send 's' SYN packets per second to the server. You have put measures in place to manage 'fSYN packets per second, and the system is designed to deal with this number without any performance issues.If 's' exceeds 'f', the network infrastructure begins to show signs of overload. The system's response timeincreases exponentially (24k), where 'k' represents each additional SYN packet above the ff limit. Now, considering 's=500' and different 'f values, in which scenario is the server most likely to experience overload and significantly increased response times?
D) f=420: The server can handle 490 SYN packets per second. With 's' exceeding 'f by 10, the response time shoots up (2410 = 1024 times the usual response time), indicating a system overload
Explanation:
A SYN flood attack is a type of denial-of-service (DoS) attack that exploits the TCP handshake process by sending a large number of SYN requests to the target server, without completing the connection. This consumes the connection state tables on the server, preventing it from accepting new connections. The attacker has crafted an automated botnet to simultaneously send 's' SYN packets per second to the server. The server can handle 'f' SYN packets per second without any performance issues. If 's' exceeds 'f', the network infrastructure begins to show signs of overload. The system's response time increases exponentially (24k), where 'k' represents each additional SYN packet above the 'f' limit.
Considering 's=500' and different 'f' values, the scenario that is most likely to cause the server to experience overload and significantly increased response times is the one where 'f=420'. This is because 's' is greater than 'f' by 80 packets per second, which means the server cannot handle the incoming traffic and will eventually run out of resources. The response time shoots up (2480 = 281,474,976,710,656 times the normal response time), indicating a system overload.
The other scenarios are less likely or less severe than the one where 'f=420'. Option A has 'f=510', which is greater than 's', so the system stays stable and the response time remains unaffected. Option B has 'f=495', which is less than 's' by 5 packets per second, so the response time drastically rises (245 = 32 times the normal response time), indicating a probable system overload, but not as extreme as option D. Option C has 'f=505', which is less than 's' by 5 packets per second, so the response time increases but not as drastically (245 = 32 times the normal response time), and the system might still function, albeit slowly.Reference:
SYN flood DDoS attack | Cloudflare
SYN flood - Wikipedia
What Is a SYN Flood Attack? | F5
What is a SYN flood attack and how to prevent it? | NETSCOUT
A) f=510: The server can handle 510 SYN packets per second, which is greater than what the attacker is sending. The system stays stable, and the response time remains unaffected
B) f=495: The server can handle 495 SYN packets per second. The response time drastically rises (245 = 32 times the normal), indicating a probable system overload
C) f=S05: The server can handle 505 SYN packets per second. In this case, the response time increases but not as drastically (245 = 32 times the normal), and the systern might still function, albeit slowly
Ammie
8 months agoBrock
8 months agoGearldine
8 months agoRory
8 months agoEmiko
8 months agoWenona
9 months agoKanisha
9 months agoMarvel
9 months agoMilly
9 months agoTammy
9 months agoEmerson
9 months agoBuffy
9 months agoKristal
9 months agoDominga
1 year agoMarya
1 year agoAvery
1 year agoDana
1 year agoMarylou
1 year agoShala
1 year agoOdette
1 year agoJames
1 year agoMargart
1 year agoFernanda
1 year agoCarlota
1 year agoAdria
1 year agoLauna
1 year ago