Author
Listed:
- Nazar Abbas Saqib
(SAUDI ARAMCO Cybersecurity Chair, Department of Networks and Communications, College of Computer Science and Information Technology, Imam Abdulrahman Bin Faisal University, P.O. Box 1982, Dammam 31441, Saudi Arabia)
- Haifa Alobiad
(College of Computer Science and IT, Imam Abdulrahman Bin Faisal University, Dammam 34212, Saudi Arabia)
- Layan Alsuliman
(College of Computer Science and IT, Imam Abdulrahman Bin Faisal University, Dammam 34212, Saudi Arabia)
- Tala Almulla
(College of Computer Science and IT, Imam Abdulrahman Bin Faisal University, Dammam 34212, Saudi Arabia)
Abstract
SYN flooding attacks remain a persistent threat to network availability, particularly in Distributed Denial-of-Service (DDoS) scenarios that exploit the TCP three-way handshake. Traditional SYN cookies mitigate half-open connection exhaustion but may exhibit limited replay resistance under certain adversarial conditions. This paper presents a nonce-enhanced, HMAC-SHA256-based SYN cookie mechanism designed to strengthen handshake validation while preserving stateless operation. The implemented framework binds each connection attempt to a time-bounded, per-session nonce and embeds a truncated HMAC within the TCP sequence number field. The mechanism is implemented and experimentally evaluated using a custom-built simulation framework, NOxSYN. Under concurrent SYN flood conditions, the enhanced design successfully validated legitimate handshakes while maintaining stable operation under adversarial load. Measured server-side cryptographic processing remained below 1 ms per connection, with stable CPU utilization during testing. These results demonstrate that nonce-based replay protection can be integrated into a SYN cookie framework while preserving scalability and stateless operation. The current evaluation focuses on implementation-level validation and performance characterization, providing a foundation for future security-oriented assessment across a broader range of replay-based attack scenarios.
Suggested Citation
Nazar Abbas Saqib & Haifa Alobiad & Layan Alsuliman & Tala Almulla, 2026.
"Enhancing SYN Cookie Security Against DDoS Attacks: Mitigating Replay Attacks with Nonce Implementation,"
Future Internet, MDPI, vol. 18(6), pages 1-26, June.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:6:p:323-:d:1967549
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:6:p:323-:d:1967549. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.