ADP SYN, ACK flood from SYN

Theirs is no way to tell if a SYN is valid or not but lets say its not your server sends a SYN,ACK waits a bit if no replay sends another waits again till a RST is sent its a low DDoS bandwidth attack that can add up so what if the USG allow the first SYN,ACK but drops the others.  

