Effectiveness of Built-in Security Protection of Microsoft’s Windows Server 2003 against TCP SYN Based DDoS Attacks
- 1
- 2
Abstract
Recent DDoS attacks against several web sites operated by SONY Playstation caused wide spread outage for several days, and loss of user account information. DDoS attacks by WikiLeaks supporters against VISA, MasterCard, and Paypal servers made headline news globally. These DDoS attack floods are known to crash, or reduce the performance of web based applications, and reduce the number of legitimate client connections/sec. TCP SYN flood is one of the common DDoS attack, and latest operating systems have some form of protection against this attack to prevent the attack in reducing the performance of web applications, and user connections. In this paper, we evaluated the performance of the TCP-SYN attack protection provided in Microsoft’s windows server 2003. It is found that the SYN attack protection provided by the server is effective in preventing attacks only at lower loads of SYN attack traffic, however this built-in protection is found to be not effective against high intensity of SYN attack traffic. Measurement results in this paper can help network operators understand the effectiveness of built-in protection mechanism that exists in millions of Windows server 2003 against one of the most popular DDoS attacks, namely the TCP SYN attack, and help enhance security of their network by additional means.
- “Transmission Control Protocol” RFC 793, Information Science Institute, University of Southern California, Los Angeles, September 1981. http://tools.ietf.org/html/rfc793
- Microsoft Corporation, “Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723),” Microsoft Security Bulletin MS09-048-Critical, 8 September 2009. http://www.microsoft.com/technet/security/Bulletin/MS09-048.mspx
- W. M. Eddy, “TCP SYN Flooding Attacks and Common Mitigations,” RFC 4987, August 2007. http://tools.ietf.org/html/rfc4987
- V. Cerf, Y. Dalal and C. Sunshine, “Specification of Internet Transmission Control Program,” RFC 675, 1974. http://tools.ietf.org/html/rfc675#section-4.2.2
- Microsoft Corporation, “Transmission Control Protocol/Internet Protocol (TCP/IP)”,Windows Server TechNet Library, 2003. http://technet.microsoft.com/en-us/library/cc759700(WS.10).aspx
- S. Shin, K. Kim and J. Jang, “D-SAT: Detecting SYN Flooding Attack by Two-Stage Statistical Approach,” The 2005 Symposium on Applications and the Internet, 31 January-4 February 2005, pp. 430-436.
- B. Lim and M. S. Uddin, “Statistical-Based SYN-Flood- ing Detection Using Programmable Network Processor,” 3rd International Conference on Information Technology and Applications, ICITA 2005, Vol. 2, 4-7 July 2005, pp. 465-470.
- R. R. Kompella, S. Singh and G. Varghese, “On Scalable Attack Detection in the Network,” Integrated Marketing Communications, IMC’04, University of California, San diego, 25-27 October 2004.
- Y. Ohsita, S. Ata and M. Murata, “Detecting Distributed Denial-of-Service Attacks by analyzing TCP SYN Packets Statistically,” Global Telecommunications Conference, 2004, GLOBECOM’04, Vol. 4, 29 November-3 December, 2004, pp. 2043-2049.
- D. M. Divakaran, H. A. Murthy and T. A. Gonsalves, “Detection of SYN Flooding Attacks Using Linear Prediction Analysis,” 14th IEEE International Conference on Networks, ICON’06, Vol. 1, September 2006, pp. 1-6.
- B. Xiao, W. Chen, Y. He and E. H.-M. Sha, “An Active Detecting Method against SYN Flooding Attack,” 11th International Conference on Parallel and Distributed Systems, Vol. 1, 20-22 July 2005, pp. 709-715.
- S. Kumar and E. Petana, “Mitigation of TCP-SYN Attack with Microsoft’s Windows XP Service Pack3 (SP2) Software,” Proceedings of the 7th International Conference on Networking, 2008, pp. 238-242.