Name: draft-poon-tcp-tstamp-mod-01
Title: Use of TCP timestamp option to defend against blind spoofing attack
State: Active
Authors: Kacheong Poon
Group: Individual Submissions (none)
Date: 2004-10-26
The US-CERT alert (TA04-111A) shows that the well-known weakness in TCP's
segment acceptance test is easier to exploit than previously thought. While
there are already mechanisms, such as RFC 2385 for BGP and IPSEC, to defend
against this kind of attack, we propose a light weight method making use of
TCP timestamp (RFC 1323) option as an alternative.
|
|
|