PacketScope · NOC Triage Lab

Traffic Triage: Fingerprinting a SYN-Flood DoS

Customers can't reach the storefront. Capture the edge traffic, isolate the TCP handshake stages by their flags, and decide what's actually breaking availability.

N10-009 4.2 · 5.5 N10-007 4.4 · 3.3 AP NET 4.1.A · 4.5.C
PacketScope 3.2 — capture: edge-mirror/vlan80 idle
Start the capture to enable the display filter.
No.TimeSourceDestinationProtoInfo
No capture running. Press Start capture to collect traffic from the edge mirror port.
Displayed
0
SYN only
0
SYN-ACK
0
ACK (est.)
0
Handshake funnel
0SYN
0SYN-ACK
0ACK
Lab worksheet0 / 7

Scenario. You're Robin Vega, on the night NOC desk at Marlowe & Finch Outfitters. The storefront web-edge-02 (203.0.113.40) is timing out for shoppers. Your probe noc-probe-07 sits on the edge mirror port (VLAN 80, EDGE-DMZ), so you can watch every packet hitting the server. Capture, then split the traffic by TCP handshake stage.

Tasks — auto-checked

  • Start the capture Collect live traffic from the edge mirror port.
  • Isolate connection requests (SYN only) SYN flag set, ACK flag clear — the start of a handshake.
  • Isolate the server's replies (SYN-ACK) SYN and ACK both set — the server answering each request.
  • Isolate established sessions (ACK only) ACK set, SYN clear — handshakes that actually completed.

Questions

0 / 7

Submit completed lab

A pseudonym only — no real name, no student ID, no email. This keeps PII out of the system.