20.01.2013 Views

Transport Layer - Freie Universität Berlin

Transport Layer - Freie Universität Berlin

Transport Layer - Freie Universität Berlin

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TCP and Security: SYN-Flood<br />

● Countermeasure: SYN cookies<br />

● Server does not creates a half-open<br />

connection<br />

● Server computes an initial sequence<br />

number y based on a hash function<br />

● This is the cookie<br />

● When client returns with ACK the<br />

server recomputes the hash<br />

function and checks it<br />

● For legitimate connection the check<br />

will be successful<br />

Client<br />

Univ.-Prof. Dr.-Ing. Jochen H. Schiller ▪ cst.mi.fu-berlin.de ▪ Telematics ▪ Chapter 8: <strong>Transport</strong> <strong>Layer</strong><br />

Server<br />

y=h()<br />

Check y<br />

8.120

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!