From the screenshot, the start of network packet number is 41115, but how can we actually detect if the attack has ended? Is there calculation to it?
And also, is this attack from the same network as the company server? From what i know, this is a 3 way handshake so the ip address of 192.168.1.20 and 192.168.1.44 are communicate to one another? Am i right?
And is the intent of this attack is’it to make the server slow down? I’m not sure about what is the intent of this attack, and what actually the attacker hope to achieve?