Refer to the exhibit. What should an engineer conclude from this Wireshark capture of suspicious network traffic?
A high volume of TCP SYN packets from numerous apparent source addresses directed at one host's HTTP port indicates a SYN flood attempt. Increasing the connection backlog and expiring or recycling old half-open TCP connections helps reduce exhaustion of the server's TCP connection queue.
Community Discussion