If the purpose of a SYN Flood attack would be to make the target unresponsive to normal traffic, same as any other DoS, wouldn't this attack generally have been directed at a public server rather than a private user; what would be the thinking behind directing such an attack at a private user?
EDIT
The firewall in question, used in a secured home office, reported a series of SYN Flood matches on various requests coming in over a ten-second period. The IP and country of origin changed with every request, so appears (obviously) not to be a direct attack. This is the only network traffic recorded that appeared to be out of whack, and none of these IPs are showing up anywhere else in the log.
What methods of analysis can I use, outside of reviewing the firewall logs, to determine if/what was done by the malicious user before or after this attack?
Here is the log file, with obvious elements obscured. The only thing to note is that the IP changed with each request. This is a static IP, which is very closely watched. Marks the first time any traffic of this nature has been flagged over a period of 12 months through this firewall (a Cisco LRT214):
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=113 ID=12552 DF PROTO=TCP SPT=53687 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=12320 DF PROTO=TCP SPT=55785 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=113 ID=26736 DF PROTO=TCP SPT=62637 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=52 ID=32708 DF PROTO=TCP SPT=59263 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=28141 DF PROTO=TCP SPT=51584 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=113 ID=11447 DF PROTO=TCP SPT=57275 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=19678 DF PROTO=TCP SPT=61655 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:01 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=117 ID=724 DF PROTO=TCP SPT=52191 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:03 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=17982 DF PROTO=TCP SPT=52394 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:03 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=1882 DF PROTO=TCP SPT=58462 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:03 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=2580 DF PROTO=TCP SPT=51861 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:03 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=5245 DF PROTO=TCP SPT=49869 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:04 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=25753 DF PROTO=TCP SPT=49344 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:04 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=12321 DF PROTO=TCP SPT=55785 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:04 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=113 ID=27245 DF PROTO=TCP SPT=62637 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:04 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=28957 DF PROTO=TCP SPT=51584 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:04 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=11518 DF PROTO=TCP SPT=62886 DPT=13766 WINDOW=63443 RES=0x00 SYN URGP=0
Aug 8 14:08:05 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=24093 DF PROTO=TCP SPT=53653 DPT=13766 WINDOW=65535 RES=0x00 SYN URGP=0
Aug 8 14:08:10 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=12322 DF PROTO=TCP SPT=55785 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:10 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=28522 DF PROTO=TCP SPT=62637 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:10 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=52 TOS=0x00 PREC=0x00 TTL=113 ID=5462 DF PROTO=TCP SPT=57172 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
Aug 8 14:08:10 2015 [ROUTER NAME OBSCURED] kernel: #warn<4> Blocked - SYN Flood: IN=eth1 SRC=[REMOTE IP OBSCURED] DST=[LOCAL IP OBSCURED] LEN=48 TOS=0x00 PREC=0x00 TTL=106 ID=29794 DF PROTO=TCP SPT=51584 DPT=13766 WINDOW=8192 RES=0x00 SYN URGP=0
EDIT
Questions have been re-combined. Will someone please remove the duplicate (which I was specifically asked to separate as a second question, by board moderators, in the first place)?
Hmm, looks like not. Whatever.