tcp synfloods with us since we have tcp attacker sends initial SYN only a lot of them never follows up doesn't need to see replies - can spoof the address very hard to track the origin down affects tcp servers - and stateful firewalls