Question: Is this possible because they are using Linux servers? The Linux kernel adopted TCP Fast Open?
https://www.ietf.org/mail-archive/web/tcpm/current/msg08204....
https://www.ietf.org/mail-archive/web/tcpm/current/msg08204....
We started blocking these large requests over 3 years ago when we started seeing them. Interestingly enough, that was a full 6-9 months before Radware wrote an article and coined the term Tsunami SYN. We just called it "big SYN". The attack is trivially easy to stop, and anyone running a client that tries a TCP Fast Open should expect failure frequently.