What is a PUSH and ACK Flood?
By flooding a server with spurious PUSH and ACK requests, an attacker can prevent the server from responding to valid traffic. This technique is called a PUSH or ACK flood.
Since PUSH and ACK messages are a part of standard traffic flow, a huge flood of these messages alone indicates abuse. Using a full-proxy architecture to manage every conversation between the client and the server can weed out abuse quickly.
Both F5 BIG-IP Local Traffic Manager (LTM) and BIG-IP Advanced Firewall Manager (AFM) are built on full-proxy architectures, so they can determine valid traffic flow and drop PUSH and ACK traffic floods so they never pass to the protected network.
