Name: draft-shepard-tcp-reassign-port-number-00
Title: Reassign Port Number option for TCP
State: Active
Authors: Timothy Shepard
Group: Individual Submissions (none)
Date: 2004-07-13
Most TCP connections are protected from spoofing attacks from off- path
attackers by their obscurity. This memo suggests that the few TCP
connections that aren't so protected today may be protected by making them
obscure by using random values for both port numbers. The obvious
difficulty with this approach is that the well-known port number is
required on the initial SYN to connect to the desired service. A TCP option
is proposed which can be used during the SYN and SYN-ACK exchange to
request (and accomplish) reassignment of the well known port number to a
random value.
|
|
|