ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › SYN flood test

Layer 4 · Transport · syn_flood

SYN flood test

The syn_flood simulation emits raw TCP SYN packets at a guaranteed rate to pressure the SYN backlog and connection table on a domain you own — real SYN packets from the worker's own address, nothing spoofed. It rehearses the classic SYN-flood failure mode while staying attributable and in-bounds.

Layer L4 Protocol TCP Command syn_flood Access Reviewed engagement

On this page

  1. What a SYN flood does
  2. How ddos-simulation.com simulates it safely
  3. What the test exercises
  4. When to run it
  5. How to run the test
  6. Reading the results
  7. Availability & limits
  8. FAQ
  9. Related simulations

What a SYN flood does

A traditional SYN flood sprays half-open connection requests with forged source addresses, filling the target's SYN backlog so it can no longer accept legitimate connections. The forged sources also make the traffic hard to trace and block.

How ddos-simulation.com simulates it safely

ddos-simulation.com pressures the same connection state without forgery: it emits raw TCP SYN packets at a guaranteed rate from the worker's real address to a single verified domain pinned to a public address, holding one raw socket for the whole task and never completing the handshake. Because the source is real, the target's SYN-ACKs return and the worker's own kernel resets them — so this is an honest SYN-rate generator rather than a spoofed backlog-exhauster — with every packet attributable and the rate held inside the domain's limits.

Authorized targets only

Every run is bound to one verified domain you have proven you own. Ownership is checked over HTTPS before anything is scheduled, and running traffic against systems you do not own or are not clearly authorized to test may be unlawful. See the Acceptable Use Policy.

What the test exercises

  • SYN backlog and half-open connection limits
  • Connection-table and conntrack capacity
  • SYN-cookie and TCP tuning under pressure
  • Firewall and load-balancer state handling
  • Time-to-recover once the test stops

When to run a SYN flood test

Run a SYN flood test when transport-layer state — not application logic — is what you need to prove out.

  • You've enabled SYN cookies, tuned the backlog, or added connection-tracking capacity and want to confirm it actually holds.
  • An edge firewall, load balancer, or DDoS scrubber sits in front and you need evidence its SYN-flood mitigation engages.
  • You're sizing headroom before a launch or a high-traffic event and want a known SYN rate the stack can absorb.

How to run a syn flood test

  1. Verify your domain. Prove ownership over HTTPS — it is self-service and takes minutes.
  2. Add the syn_flood command to a timeline in the portal and set the target port, rate, and duration.
  3. Set health thresholds. Choose the error-rate, latency, or status-code limits at which the test should abort itself.
  4. Run and watch. Bounded workers are provisioned minutes before start and torn down the moment the last task ends, while metrics stream live.
  5. Read the results. Review the recorded latency, status codes, and worker timeline to find where your service starts to bend.

Configure a syn flood test in the portal →

Reading the results

Resilient: The listener keeps accepting legitimate connections throughout, SYN-ACK latency stays flat, and backlog and connection-tracking counters stay well below their limits.

Under strain: New connections start timing out, the accept queue or conntrack table fills, or softirq CPU spikes — signs the SYN path, not bandwidth, is the bottleneck.

Availability & limits

SYN floods are reviewed and approved before they run (a manual review) and are priced per engagement — request a quote.

Frequently asked questions

Does this spoof source addresses like a real SYN flood?

No. The worker sends real SYN packets from its own address at a guaranteed rate — nothing is spoofed. Because the source is real, the target's SYN-ACKs come back and the local kernel resets them, so it acts as a SYN-rate generator rather than a spoofed half-open backlog exhauster; it still exercises the SYN path, backlog, and SYN-cookie handling.

Why does this need review?

SYN pressure targets transport-layer state that shared infrastructure may rely on, so it is gated behind a manual review before it can run.

Related simulations

TCP flag flood test Flood a target you own with crafted TCP control segments — SYN, ACK, RST, and FIN — to pressure stateful firewalls and connection-tracking tables. UDP flood test Simulate a bounded UDP flood against infrastructure you own to probe UDP ingress filtering, bandwidth headroom, and rate limits. HTTPS flood test Run an authorized HTTPS flood test against a domain you own.

Rehearse the syn flood against infrastructure you own — bounded, monitored, and stopped the instant you have your answer.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA