1

enter image description here

The attacker spoofs SYN packets to attack a server.

In this document:

Spoofed Attack: A malicious user can also spoof the IP address on each SYN packet they send in order to inhibit mitigation efforts and make their identity more difficult to discover. While the packets may be spoofed, those packets can potentially be traced back to their source. It’s difficult to do this sort of detective work but it’s not impossible, especially if Internet service providers (ISPs) are willing to help.

I only can think that all the ISPs in cooperation can provide the packet's path. Are ISPs providing the path of spoofed IPs the only way to trace the attack source?

schroeder
  • 123,438
  • 55
  • 284
  • 319
244boy
  • 935
  • 2
  • 6
  • 8

0 Answers0