TCP-SYN Attack on McAfee SecurityCenter
TCP-SYN flood is Layer-4 Denial of Service attack. TCP-SYN attack traffic is sent to the iMac deploying WindowsXP-SP2 with McAfee Firewall at default settings and there is no option to avoid the TCP-SYN attack. After we started the TCP-SYN attack, the system froze giving us the BSoD again, as in the case of Ping attack. The processor utilization was just 50% for 1 Gbps of traffic and the Pool NonPaged Allocs and Bytes were plotted as shown in the Figures 15 and 16. These are very much similar to the case where Ping attack was done and the reason was the same. McAfee Firewall is creating NonPaged allocations that are growing unboundedly in the main memory and cannot be paged out. The operating system cannot allocate more than the assigned memory so it is causing in system freeze and resulting in BSoD. It can be observed that it took 8 seconds for the system to freeze from the Figures 15 and 16.