ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › TCP Zero-Window starvation

Layer 7 · Application / Transport · tcp_zero_window_starvation

TCP Zero-Window starvation test

The tcp_zero_window_starvation simulation connects to your HTTP/HTTPS service, requests large resources, and immediately advertise a TCP receive window of 0 bytes, testing kernel send-buffer retention and client write timeouts.

Layer L7 Protocol TCP / HTTP Command tcp_zero_window_starvation Access Self-service / Quote

On this page

  1. What Zero-Window starvation does
  2. How ddos-simulation.com simulates it safely
  3. What the test exercises
  4. When to run it
  5. How to run the test
  6. Reading the results
  7. Related simulations

What Zero-Window starvation does

When a TCP receiver advertises win 0, the sender is prohibited by the TCP standard from transmitting further payload bytes until a window update arrives. While waiting, the server must keep the full pending response in memory (the socket send buffer) and maintain active worker state. By opening thousands of zero-window connections, an attacker exhausts origin RAM and socket descriptors with minimal client bandwidth.

How ddos-simulation.com simulates it safely

ddos-simulation.com establishes real, non-spoofed TCP connections to your verified domain and precisely controls TCP window advertisement headers within configured concurrency bounds.

What the test exercises

  • Origin web server write timeout enforcement (e.g. NGINX send_timeout, Apache Timeout)
  • Kernel TCP socket send-buffer limits (tcp_wmem, SO_SNDBUF)
  • Reverse proxy / CDN buffer offloading and backpressure isolation
  • Worker thread release under zero-throughput socket holds

When to run this test

  • Tuning web server and reverse proxy send timeouts.
  • Validating that slow clients cannot pin database-rendered or dynamic file download workers indefinitely.

How to run the test

  1. Verify domain ownership in the portal.
  2. Add tcp_zero_window_starvation to your timeline with target path and concurrency.
  3. Observe origin worker memory and socket table utilization in real time.

Reading the results

Resilient: The server detects stalled progress and terminates the connection cleanly when the configured send timeout expires (typically 10–30s), releasing memory.

Under strain: Worker threads remain locked indefinitely, socket buffer allocations accumulate in the kernel, and new connections are refused.

Related simulations

Slow read test Tests slow response consumption under tiny window constraints. Slowloris test Holds connections open with slow header transmission. Established connection flood Pressures connection-tracking tables with idle TCP sessions.

Test your origin send-buffer resilience safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA