asked 2023-12-23 16:53:49 +0000

Mubashir

How to identify sync flood attack or DDoS attack using wire shark

What are the characteristics of a sync flood or DDoS attack according to you?

Jaap ( 2023-12-24 13:02:57 +0000 )

alert appeared for DDoS attack then I used wire shark it shows multiple sync packets from the trusted IP/ physical address. I want to confirm that how I consider that it is a sync flood attack?

Mubashir ( 2023-12-24 15:14:38 +0000 )

Alert from what?

Jaap ( 2023-12-24 16:06:58 +0000 )

I would start with what is on DDOS. Afterwards, think about how to look for the behavior using Wireshark.

BigFatCat ( 2023-12-24 16:45:38 +0000 )

Do you mean "SYN Flood (TCP/SYN)"?

Chuckc ( 2023-12-25 00:06:29 +0000 )