TCP - Termination

The query FIN refers to the Finish flag in the Transmission Control Protocol (TCP) header, which is crucial for reliably terminating a TCP connection. It is also utilized by attackers in various network scanning and evasion techniques.

Here is a detailed explanation of the FIN flag based on the sources:

400

1. Definition and Role in TCP Communication

The FIN flag is one of the six control flags in the TCP header that manage the connection between two hosts.

2. Exploitation in Network Scanning (Stealth Techniques)

Attackers leverage the FIN flag in stealth scanning methods because many security mechanisms, such as firewalls and Intrusion Detection Systems (IDS), are designed to detect the initial SYN packet used in traditional connection attempts.

A. FIN Scan

The FIN Scan is an Inverse TCP Flag Scan technique categorized as a Stealth TCP Scanning Method.

B. Xmas Scan

The FIN flag is also used as part of the Xmas Scan, another inverse TCP scanning technique.

3. Role in Denial-of-Service (DoS) Attacks

The FIN flag is also utilized by attackers in denial-of-service (DoS) and Spoofed Session Flood attacks:

400