{"id":182,"date":"2026-07-17T09:00:00","date_gmt":"2026-07-17T09:00:00","guid":{"rendered":"https:\/\/backendside.com\/blog\/?p=182"},"modified":"2026-07-21T18:01:49","modified_gmt":"2026-07-21T18:01:49","slug":"detect-syn-udp-icmp-floods-sflow","status":"publish","type":"post","link":"https:\/\/backendside.com\/blog\/2026\/07\/17\/detect-syn-udp-icmp-floods-sflow\/","title":{"rendered":"Spotting SYN, UDP, and ICMP Floods in Real Time with Flow Telemetry"},"content":{"rendered":"<p class=\"lead\">Volumetric and protocol floods are the blunt instruments of the DDoS world&mdash;and they still work. A SYN flood can exhaust a server&rsquo;s connection table; a UDP or ICMP flood can fill your uplink with pure noise. The difference between a shrug and an outage is often just <strong>how fast you notice<\/strong>. This is where flow telemetry earns its keep. Here&rsquo;s how the common floods work and how to catch them in real time.<\/p>\n<figure style=\"margin:2rem 0;text-align:center;\">\n  <img decoding=\"async\" src=\"https:\/\/backendside.com\/blog\/wp-content\/uploads\/2026\/07\/distributed-flood-attack-diagram.png\" alt=\"Diagram of a distributed flood attack with many attacker sources sending flood traffic through ISP networks to saturate a single victim's link\" style=\"max-width:100%;height:auto;border-radius:8px;\"><figcaption style=\"font-size:.85rem;color:#6b6a66;margin-top:.5rem;\">Floods win on volume and speed&mdash;detection has to be faster.<\/figcaption><\/figure>\n<h2>The floods you need to recognize<\/h2>\n<ul>\n<li><strong>SYN flood.<\/strong> A storm of TCP SYN packets (often spoofed) opens half-connections the server must hold open, exhausting its state table. The fingerprint: a surge of SYNs with few completing handshakes.<\/li>\n<li><strong>UDP flood.<\/strong> High-rate UDP packets, frequently to random ports, that force the target to churn generating &ldquo;port unreachable&rdquo; replies and simply saturate the pipe.<\/li>\n<li><strong>ICMP flood.<\/strong> A deluge of ping\/echo traffic consuming bandwidth and CPU.<\/li>\n<li><strong>ACK\/RST flood.<\/strong> Floods of TCP ACK or RST packets that bypass simple SYN-based defenses and hammer stateful devices.<\/li>\n<li><strong>HTTP flood.<\/strong> A wave of seemingly legitimate requests aimed at exhausting application resources.<\/li>\n<\/ul>\n<h2>Why sFlow is built for this<\/h2>\n<p>Floods are, by definition, high-volume and sudden&mdash;which plays directly to sFlow&rsquo;s strengths. Sampling in hardware means even a 100G flood doesn&rsquo;t blind your switch, and the real-time streaming means you see the rate climb the instant it starts, not after a flow cache flushes. The signal is loud: packet rates and connection patterns spike far past anything normal, with lopsided flag ratios (all SYN, all ACK) that legitimate traffic never shows.<\/p>\n<h2>Turn the signal into an alert<\/h2>\n<p><strong>BackendSide sFlow Collector &amp; Analyzer<\/strong> includes dedicated flood detectors&mdash;SYN, UDP, ICMP, ACK\/RST, and HTTP&mdash;each watching your live sFlow feed for the rate and pattern that defines that attack. Instead of eyeballing a bandwidth graph and hoping, you get an alert with the target, the source pattern, and a severity tier, in the seconds that matter. And because alerts are grouped into episodes, a flood shows up as <em>one<\/em> escalating event with an occurrence count&mdash;not ten thousand duplicate rows burying your console.<\/p>\n<figure style=\"margin:2rem 0;text-align:center;\">\n  <img decoding=\"async\" src=\"https:\/\/backendside.com\/blog\/wp-content\/uploads\/2026\/07\/threat-overview-flood-indicators.png\" alt=\"BackendSide sFlow Threat Overview page showing port-scan suspects ranked by scanner with ports, targets and severity, a SYN flood indicators panel, and a severity distribution breakdown\" style=\"max-width:100%;height:auto;border-radius:8px;\"><figcaption style=\"font-size:.85rem;color:#6b6a66;margin-top:.5rem;\">The Threat Overview surfaces flood and scan indicators with severity tiers&mdash;clear signal, not a wall of noise.<\/figcaption><\/figure>\n<div style=\"border:1px solid #c5d3f8;background:linear-gradient(135deg,#eef2fd 0%,#ffffff 72%);border-radius:14px;padding:1.5rem 1.65rem;margin:2rem 0;\">\n<div style=\"font-size:.7rem;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:#2d5be3;margin-bottom:.55rem;\">&#128295; BackendSide Tool<\/div>\n<h4 style=\"margin:0 0 .45rem;font-size:1.15rem;color:#1a1916;font-weight:700;\">BackendSide sFlow Collector &amp; Analyzer &mdash; Turn a Flood Into a Single Actionable Alert<\/h4>\n<p style=\"margin:0 0 1.05rem;color:#3d3c38;font-size:.92rem;line-height:1.65;\"><strong>BackendSide sFlow Collector &amp; Analyzer<\/strong> includes dedicated flood detectors &mdash; SYN, UDP, ICMP, ACK\/RST and HTTP &mdash; each watching your live sFlow feed for the rate and pattern that defines that attack. You get an alert with the target, the source pattern and a severity tier in the seconds that matter, and because alerts are grouped into episodes, a flood shows up as one escalating event with an occurrence count instead of ten thousand duplicate rows.<\/p>\n<p>  <a href=\"https:\/\/backendside.com\/backendsidesflow.php\" style=\"display:inline-flex;align-items:center;gap:.4rem;background:#2d5be3;color:#ffffff;font-weight:600;font-size:.85rem;padding:.6rem 1.2rem;border-radius:6px;text-decoration:none;\">Explore BackendSide sFlow Collector &amp; Analyzer &rarr;<\/a>\n<\/div>\n<h2>The bottom line<\/h2>\n<p>Floods aren&rsquo;t subtle&mdash;they&rsquo;re fast. The winning move is early detection, and flow telemetry gives you exactly that: a real-time view that lights up the moment traffic stops looking like traffic and starts looking like an attack. Pair it with detectors built for each flood type, and you turn &ldquo;why is everything down?&rdquo; into &ldquo;we saw it at packet one.&rdquo;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Volumetric and protocol floods are the blunt instruments of the DDoS world, and they still work. A SYN flood exhausts a connection table; a UDP or ICMP flood fills your uplink with noise. The difference between a shrug and an outage is how fast you notice. Here is how the common floods work and how to catch them in real time with sFlow.<\/p>\n","protected":false},"author":1,"featured_media":186,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-182","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-networking","category-security"],"_links":{"self":[{"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/posts\/182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/comments?post=182"}],"version-history":[{"count":1,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/posts\/182\/revisions"}],"predecessor-version":[{"id":185,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/posts\/182\/revisions\/185"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/media\/186"}],"wp:attachment":[{"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/media?parent=182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/categories?post=182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/backendside.com\/blog\/wp-json\/wp\/v2\/tags?post=182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}