Chapter 7 Firewall for FortiOS 5.0 : Network defense : Defending against DoS attacks : DDoS SYN flood
  
DDoS SYN flood
The most severe form of SYN attack is the distributed SYN flood, one variety of distributed denial of service attack (DDoS). Like the SYN flood, the target receives a flood of SYN packets and the ACK+SYN replies are never answered. The attack is distributed across multiple sources sending SYN packets in a coordinated attack.
Figure 175: Multiple attackers launch a distributed SYN flood
The distributed SYN flood is more difficult to defend against because multiple clients are capable of creating a larger volume of SYN packets than a single client. Even if the server can cope, the volume of traffic may overwhelm a point in the network upstream of the targeted server. The only defence against this is more bandwidth to prevent any choke‑points.