# TCP SYN timeouts

**URL:** <https://community.zeek.org/t/tcp-syn-timeouts/1766>\
**Category:** Development\
**Tags:** development\
**Created:** [December 14, 2010, 6:55pm UTC](https://community.zeek.org/t/tcp-syn-timeouts/1766 "2010-12-14T18:55:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gregor\_Maier](https://avatars.discourse-cdn.com/v4/letter/g/94ad74/32.png) [@Gregor\_Maier](https://community.zeek.org/u/Gregor_Maier)\
**Post date:** [December 14, 2010, 6:55pm UTC](https://community.zeek.org/t/tcp-syn-timeouts/1766/1 "2010-12-14T18:55:45Z")

</div>

Hi,

while working on [http://tracker.icir.org/bro/ticket/338](http://tracker.icir.org/bro/ticket/338) I found some  
oddities. But see also [http://tracker.icir.org/bro/ticket/77](http://tracker.icir.org/bro/ticket/77)

Bro has:  
&nbsp;&nbsp;\* tcp\_SYN\_timeout  
&nbsp;&nbsp;\* tcp\_attempt\_delay  
both are set to 5sec.

Both can time out a TCP connection for which only SYNs are seen.  
However, tcp\_attempt\_delay is used only when the the connection\_attempt  
event has a script level handler. tcp\_attempt\_delay is installed on the  
\*first\* SYN packet. Thus tcp\_attempt\_delay always triggers relative to  
the first SYN packet (and did this even before #77 was applied. I.e.,  
#77 did not change the timer behavior)  
Note that conn.bro has a connection\_attempt handler.

tcp\_SYN\_timeout is used when TCP\_Analyzer is instantiated to set the  
ExpireTimer() (which can also happen on a pure data packet, BTW). The  
ExpireTimer only does any "expiring"  
&nbsp;&nbsp;&nbsp;&nbsp;if ( Conn()-\>LastTime() + tcp\_connection\_linger \< t )  
(so, no check for tcp\_SYN\_timeout). However, ExpireTimer() checks  
whether there is an connection\_attempt handler and if there's one it  
will not generate connection\_timeout() events for connections that only  
had SYNs and no other packets. (ExpireTimer otherwise only handles  
connections for which at least one side is already closed)

Then there's also the tcp\_inactivity\_timeout, which is set to 5min and  
managed in Conn.cc.

There's a dated documentation (pre-DPD) in the Wiki concerning these  
timers: [http://www.bro-ids.org/wiki/index.php/Connection\_Timers](http://www.bro-ids.org/wiki/index.php/Connection_Timers)  
It seems that originally  
&nbsp;&nbsp;tcp\_connection\_linger \< tcp\_SYN\_timeout \< tcp\_attempt\_delay  
which makes sense given the way these timers interact, but since we now  
have  
&nbsp;&nbsp;tcp\_SYN\_timeout == tcp\_attempt\_delay \< tcp\_connection\_linger  
the overall timer behavior is weird.

Note, the connection compressor currently \*only\* uses tcp\_attempt\_delay,  
and bases it on the time of the last SYN packet.

So, the question is: what should we do?

cu  
Gregor

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/tcp-syn-timeouts/1766/2 "2022-05-06T15:39:22Z")

</div>


