SYN
In short: The first packet in the TCP three-way handshake — with it, the client signals the wish to establish a connection (“synchronise”).
In more detail: The SYN packet contains a random initial sequence number that the client will use for this connection. The server answers with SYN-ACK. A flood of pointless SYN packets without a concluding ACK is the basis of the classic “SYN flood” DDoS attack.
In Depth
The random initial sequence number in the SYN packet (“initial sequence number”, ISN) doesn’t just serve to track ordering during the connection, but also has a security function: if the sequence number were predictable (e.g. always starting at 0), an attacker could theoretically hijack other people’s TCP connections by injecting packets with a guessed sequence number (“TCP sequence number prediction attack”). Modern operating systems therefore generate the ISN in a cryptographically random way.
A “half-open” connection attempt arises when a SYN is sent but the connection is never completed with a final ACK — that’s exactly the core of a SYN flood attack: the attacker sends masses of SYN packets (often with a forged source IP) but leaves the server hanging in the SYN-ACK waiting state until its limited connection table is full and no real users get through any more — a form of DDoS that specifically exploits the resource management of the TCP handshake instead of simply clogging bandwidth.
See also: SYN-ACK, ACK, Three-way handshake