An online store as a web application is protected by automated technical solutions that detect and prevent web-based attacks. However, the front end web application firewall seems not performing well so that the online store is suffering from TCP SYN flooding attacks. Which of the following is the most likely symptom?
A. The CPU utilization of the web server will surge.
B. The bandwidth of the public-facing connection gets exhausted.
C. The memory of the backlog queue to maintain all half-open connections depletes.
D. The hard drives of the web server will work at high utilization for memory paging.

My suggested answer is C. The memory of the backlog queue to maintain all half-open connections depletes.

Many people think that TCP SYN flooding attacks will hinder availability because of network bandwidth exhaustion. However, it’s not the case. The bandwidth requirement of the three-way handshake is lightweight. The denial of service results from the fact that legitimate new connections are blocked because the backlog queue or Transmission Control Block (TCB) table is depleted.

The CPU utilization may raise or surge, but it depends on the computing resource a system has. Some systems have one CPU only, while others may have multiple cores or even multiple processors. No matter how many CPUs or processors a system has, the size of the TCB table can be fixed and soon depleted when facing TCP SYN flooding attacks.



在線商店作為Web應用程序受到自動技術解決方案的保護,該技術解決方案可以檢測和阻止基於Web的攻擊。 但是,前端Web應用程序防火牆的性能似乎不如預期,因此在線商店正遭受TCP SYN泛洪攻擊。 以下哪項是最可能的症狀?
A. Web服務器的CPU使用率將激增。
B. 面向公眾的連接的頻寬將被耗盡。
C. 維持所有半開連接的等待佇列的記憶體存將被耗盡。
D. Web服務器的硬碟將以高利用率工作以進行記憶體分頁。


