Background
The Tsunami SYN Flood Attack is an intriguing variant of the traditional SYN flood attack. We believe that attackers are trying to challenge protected environments that would typically block a classic SYN flood but not this variant. In contrast, the Tsunami SYN flood can cause internet pipe saturation. Unlike other known pipe saturation offenses using mostly UDP traffic, the Tsunami SYN flood attack is carried over the more common TCP protocol. We have noticed attacks on entire IP and port ranges, again trying to bypass traditional SYN flood protection expecting the attack on a specific IP and port.
Additional Information