{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:44:16Z","timestamp":1782834256260,"version":"3.54.5"},"reference-count":62,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2013,4,1]],"date-time":"2013-04-01T00:00:00Z","timestamp":1364774400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100003977","name":"Israel Science Foundation","doi-asserted-by":"publisher","award":["1354\/11"],"award-info":[{"award-number":["1354\/11"]}],"id":[{"id":"10.13039\/501100003977","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006245","name":"Ministry of Science and Technology, Israel","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006245","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100021796","name":"Check Point Institute for Information Security","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100021796","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2013,4]]},"abstract":"<jats:p>\n            We show that fragmented IPv4 and IPv6 traffic is vulnerable to effective interception and denial-of-service (DoS) attacks by an\n            <jats:italic>off-path<\/jats:italic>\n            attacker. Specifically, we demonstrate a weak attacker intercepting more than 80% of the data between peers and causing over 94% loss rate.\n          <\/jats:p>\n          <jats:p>We show that our attacks are practical through experimental validation on popular industrial and open-source products, with realistic network setups that involve NAT or tunneling and include concurrent legitimate traffic as well as packet losses. The interception attack requires a zombie agent behind the same NAT or tunnel-gateway as the victim destination; the DoS attack only requires a puppet agent, that is, a sandboxed applet or script running in web-browser context.<\/jats:p>\n          <jats:p>The complexity of our attacks depends on the predictability of the IP Identification (ID) field which is typically implemented as one or multiple counters, as allowed and recommended by the IP specifications. The attacks are much simpler and more efficient for implementations, such as Windows, which use one ID counter for all destinations. Therefore, much of our focus is on presenting effective attacks for implementations, such as Linux, which use per-destination ID counters.<\/jats:p>\n          <jats:p>We present practical defenses for the attacks presented in this article, the defenses can be deployed on network firewalls without changes to hosts or operating system kernel.<\/jats:p>","DOI":"10.1145\/2445566.2445568","type":"journal-article","created":{"date-parts":[[2013,4,9]],"date-time":"2013-04-09T12:17:58Z","timestamp":1365509878000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Fragmentation Considered Vulnerable"],"prefix":"10.1145","volume":"15","author":[{"given":"Yossi","family":"Gilad","sequence":"first","affiliation":[{"name":"Bar-Ilan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amir","family":"Herzberg","sequence":"additional","affiliation":[{"name":"Bar-Ilan University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2013,4]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Advanced Network Architecture Group. 2012. ANA spoofer project. http:\/\/spoofer.csail.mit.edu\/summary.php.  Advanced Network Architecture Group. 2012. ANA spoofer project. http:\/\/spoofer.csail.mit.edu\/summary.php."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455518.1455524"},{"key":"e_1_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Arends R. Austein R. Larson M. Massey D. and Rose S. 2005. DNS security introduction and requirements. RFC 4033 (Proposed Standard). (Updated by RFC 6014).  Arends R. Austein R. Larson M. Massey D. and Rose S. 2005. DNS security introduction and requirements. RFC 4033 (Proposed Standard). (Updated by RFC 6014).","DOI":"10.17487\/rfc4033"},{"key":"e_1_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Audet F. and Jennings C. 2007. Network address translation (NAT) behavioral requirements for unicast UDP. RFC 4787 (Best Current Practice).  Audet F. and Jennings C. 2007. Network address translation (NAT) behavioral requirements for unicast UDP. RFC 4787 (Best Current Practice).","DOI":"10.17487\/rfc4787"},{"key":"e_1_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Baker F. and Savola P. 2004. Ingress filtering for multihomed networks. RFC 3704 (Best Current Practice).   Baker F. and Savola P. 2004. Ingress filtering for multihomed networks. RFC 3704 (Best Current Practice).","DOI":"10.17487\/rfc3704"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637243"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644936"},{"key":"e_1_2_1_8_1","unstructured":"CAIDA. 2012. Anonymized internet traces 2012 dataset. http:\/\/www.caida.org\/data\/passive\/passive_2012_dataset.xml.  CAIDA. 2012. Anonymized internet traces 2012 dataset. http:\/\/www.caida.org\/data\/passive\/passive_2012_dataset.xml."},{"key":"e_1_2_1_9_1","unstructured":"CERT. 1997. Teardrop DoS attack. http:\/\/www.cert.org\/advisories\/CA-1997-28.html.  CERT. 1997. Teardrop DoS attack. http:\/\/www.cert.org\/advisories\/CA-1997-28.html."},{"key":"e_1_2_1_10_1","unstructured":"Cisco Systems. 2006. Configuring dynamic ARP inspection. http:\/\/www.cisco.com\/en\/US\/docs\/switches\/lan\/catalyst4500\/12.1\/19ew\/configuration\/guide\/dynarp.html.  Cisco Systems. 2006. Configuring dynamic ARP inspection. http:\/\/www.cisco.com\/en\/US\/docs\/switches\/lan\/catalyst4500\/12.1\/19ew\/configuration\/guide\/dynarp.html."},{"key":"e_1_2_1_11_1","unstructured":"Cisco Systems. 2007. Pre-Fragmentation for IPsec VPNs. http:\/\/www.ciscosystems.cd\/en\/US\/docs\/ios\/sec_secure_connectivity\/configuration\/guide\/sec_pre_frag_vpns.pdf.  Cisco Systems. 2007. Pre-Fragmentation for IPsec VPNs. http:\/\/www.ciscosystems.cd\/en\/US\/docs\/ios\/sec_secure_connectivity\/configuration\/guide\/sec_pre_frag_vpns.pdf."},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Conta A. Deering S. and Gupta M. 2006. Internet control message protocol (ICMPv6) for the internet protocol version 6 (IPv6) specification. RFC 4443 (Draft Standard). (Updated by RFC 4884).  Conta A. Deering S. and Gupta M. 2006. Internet control message protocol (ICMPv6) for the internet protocol version 6 (IPv6) specification. RFC 4443 (Draft Standard). (Updated by RFC 4884).","DOI":"10.17487\/rfc4443"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the USENIX Workshop on Steps to Reducing Unwanted Traffic on the Internet (STRUTI). 39--44","author":"Cooke E."},{"key":"e_1_2_1_14_1","unstructured":"Deering S. and Hinden R. 1998. Internet protocol version 6 (IPv6) specification. RFC 2460 (Draft Standard). (Updated by RFCs 5095 5722 5871 6437).   Deering S. and Hinden R. 1998. Internet protocol version 6 (IPv6) specification. RFC 2460 (Draft Standard). (Updated by RFCs 5095 5722 5871 6437)."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1516539.1516541"},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Farinacci D. Li T. Hanks S. Meyer D. and Traina P. 2000. Generic routing encapsulation (GRE). RFC 2784 (Proposed Standard). (Updated by RFC 2890).   Farinacci D. Li T. Hanks S. Meyer D. and Traina P. 2000. Generic routing encapsulation (GRE). RFC 2784 (Proposed Standard). (Updated by RFC 2890).","DOI":"10.17487\/rfc2784"},{"key":"e_1_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Ferguson P. and Senie D. 2000. Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing. RFC 2827 (Best Current Practice).   Ferguson P. and Senie D. 2000. Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing. RFC 2827 (Best Current Practice).","DOI":"10.17487\/rfc2827"},{"key":"e_1_2_1_18_1","unstructured":"Gibson S. 2005. ARP poisoning report. http:\/\/www.grc.com\/nat\/arp.htm.  Gibson S. 2005. ARP poisoning report. http:\/\/www.grc.com\/nat\/arp.htm."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies.","author":"Gilad Y."},{"key":"e_1_2_1_20_1","unstructured":"Gilad Y. and Herzberg A. 2012a. Fragmentation considered vulnerable - Tech. rep. http:\/\/u.cs.biu.ac.il\/~herzbea\/security\/12-03&percnt;20fragmentation.pdf.  Gilad Y. and Herzberg A. 2012a. Fragmentation considered vulnerable - Tech. rep. http:\/\/u.cs.biu.ac.il\/~herzbea\/security\/12-03&percnt;20fragmentation.pdf."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies (WOOT). 41--52","author":"Gilad Y."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31680-7_6"},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Gont F. 2011. Security assessment of the internet protocol version 4. RFC 6274 (Informational).  Gont F. 2011. Security assessment of the internet protocol version 4. RFC 6274 (Informational).","DOI":"10.17487\/rfc6274"},{"key":"e_1_2_1_24_1","unstructured":"Gont F. 2012. Security implications of predictable fragment identification values. Internet-draft of the IETF IPv6 maintenance working group (6man). (Expires September 30 2012).  Gont F. 2012. Security implications of predictable fragment identification values. Internet-draft of the IETF IPv6 maintenance working group (6man). (Expires September 30 2012)."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076450.2076456"},{"key":"e_1_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Heffner J. Mathis M. and Chandler B. 2007. IPv4 reassembly errors at high data rates. RFC 4963 (Informational).  Heffner J. Mathis M. and Chandler B. 2007. IPv4 reassembly errors at high data rates. RFC 4963 (Informational).","DOI":"10.17487\/rfc4963"},{"key":"e_1_2_1_27_1","unstructured":"Herzberg A. and Shulman H. 2012a. Fragmentation considered poisonous. CoRR abs\/1205.4011.  Herzberg A. and Shulman H. 2012a. Fragmentation considered poisonous. CoRR abs\/1205.4011."},{"key":"e_1_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Herzberg A.\n     and \n      \n      \n      Shulman H\n      \n  \n  . \n  2012\n  b. Security of patched DNS. In Proceedings of the ESORICS. S. Foresti M. Yung and F. Martinelli Eds. Lecture Notes in Computer Science Series vol. \n  7459 Springer 271--288.  Herzberg A. and Shulman H. 2012b. Security of patched DNS. In Proceedings of the ESORICS . S. Foresti M. Yung and F. Martinelli Eds. Lecture Notes in Computer Science Series vol. 7459 Springer 271--288.","DOI":"10.1007\/978-3-642-33167-1_16"},{"key":"e_1_2_1_29_1","unstructured":"Hollis K. 1997. The Rose attack explained. http:\/\/digital.net\/~gandalf\/Rose_Frag_Attack_Explained.htm.  Hollis K. 1997. The Rose attack explained. http:\/\/digital.net\/~gandalf\/Rose_Frag_Attack_Explained.htm."},{"key":"e_1_2_1_30_1","first-page":"3","article-title":"Anatomy: A look inside network address translators","volume":"7","author":"Huston G.","year":"2004","journal-title":"Internet Prot. J."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298321"},{"key":"e_1_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Kaufman C. Hoffman P. Nir Y. and Eronen P. 2010. Internet key exchange protocol version 2 (IKEv2). RFC 5996 (Proposed Standard). (Updated by RFC 5998).  Kaufman C. Hoffman P. Nir Y. and Eronen P. 2010. Internet key exchange protocol version 2 (IKEv2). RFC 5996 (Proposed Standard). (Updated by RFC 5998).","DOI":"10.17487\/rfc5996"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948113"},{"key":"e_1_2_1_34_1","unstructured":"Kenney M. 1996. Ping o\u2019 Death. http:\/\/www.insecure.org\/sploits\/ping-o-death.html.  Kenney M. 1996. Ping o\u2019 Death. http:\/\/www.insecure.org\/sploits\/ping-o-death.html."},{"key":"e_1_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Kent C. A. and Mogul J. C. 1987. Fragmentation considered harmful. res. rep. 87\/3 Western Research Lab.  Kent C. A. and Mogul J. C. 1987. Fragmentation considered harmful. res. rep. 87\/3 Western Research Lab.","DOI":"10.1145\/55482.55524"},{"key":"e_1_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Kent S. and Seo K. 2005. Security architecture for the internet protocol. RFC 4301 (Proposed Standard).  Kent S. and Seo K. 2005. Security architecture for the internet protocol. RFC 4301 (Proposed Standard).","DOI":"10.17487\/rfc4301"},{"key":"e_1_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Killalea T. 2000. Recommended internet service provider security services and procedures. RFC 3013. (Proposed Standard).   Killalea T. 2000. Recommended internet service provider security services and procedures. RFC 3013. (Proposed Standard).","DOI":"10.17487\/rfc3013"},{"key":"e_1_2_1_38_1","unstructured":"Klein A. 2007. OpenBSD DNS cache poisoning and multiple O\/S predictable IP ID vulnerability. http:\/\/www.trusteer.com\/docs\/dnsopenbsd.html.  Klein A. 2007. OpenBSD DNS cache poisoning and multiple O\/S predictable IP ID vulnerability. http:\/\/www.trusteer.com\/docs\/dnsopenbsd.html."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/863955.863966"},{"key":"e_1_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Lahey K. 2000. TCP problems with path MTU discovery. RFC 2923 (Informational).   Lahey K. 2000. TCP problems with path MTU discovery. RFC 2923 (Informational).","DOI":"10.17487\/rfc2923"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533063"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1137\/0217022"},{"key":"e_1_2_1_43_1","unstructured":"Lyon G. 2009. Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. http:\/\/nmap.org\/book\/.   Lyon G. 2009. Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning . http:\/\/nmap.org\/book\/."},{"key":"e_1_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Maier G. Schneider F. and Feldmann A. 2011. NAT Usage in Residential Broadband Networks. In Passive and Active Measurement. Springer 32--41.   Maier G. Schneider F. and Feldmann A. 2011. NAT Usage in Residential Broadband Networks. In Passive and Active Measurement . Springer 32--41.","DOI":"10.1007\/978-3-642-19260-9_4"},{"key":"e_1_2_1_45_1","volume-title":"RFC 1981 (Draft Standard).","author":"McCann J."},{"key":"e_1_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Mogul J. and Deering S. 1990. Path MTU discovery. RFC 1191 (Draft Standard).   Mogul J. and Deering S. 1990. Path MTU discovery. RFC 1191 (Draft Standard).","DOI":"10.17487\/rfc1191"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/505659.505664"},{"key":"e_1_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Postel J. 1980. User datagram protocol. RFC 768 (Standard).   Postel J. 1980. User datagram protocol. RFC 768 (Standard).","DOI":"10.17487\/rfc0768"},{"key":"e_1_2_1_49_1","unstructured":"Postel J. 1981a. Internet control message protocol. RFC 792 (Standard). (Updated by RFCs 950 4884).   Postel J. 1981a. Internet control message protocol. RFC 792 (Standard). (Updated by RFCs 950 4884)."},{"key":"e_1_2_1_50_1","unstructured":"Postel J. 1981b. Internet protocol. RFC 791 (Standard). (Updated by RFC 1349).  Postel J. 1981b. Internet protocol. RFC 791 (Standard). (Updated by RFC 1349)."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.29"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382258"},{"key":"e_1_2_1_53_1","unstructured":"Ruderman J. 2001. Same origin policy for JavaScript. https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript.  Ruderman J. 2001. Same origin policy for JavaScript. https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript."},{"key":"e_1_2_1_54_1","unstructured":"Sanfilippo S. 1998. About the IP header ID. http:\/\/www.kyuzz.org\/antirez\/papers\/ipid.html.  Sanfilippo S. 1998. About the IP header ID. http:\/\/www.kyuzz.org\/antirez\/papers\/ipid.html."},{"key":"e_1_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Savola P. 2006. MTU and fragmentation issues with in-the-network tunneling. RFC 4459 (Informational).  Savola P. 2006. MTU and fragmentation issues with in-the-network tunneling. RFC 4459 (Informational).","DOI":"10.17487\/rfc4459"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2002.805028"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102170"},{"key":"e_1_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Srisuresh P. and Egevang K. 2001. Traditional IP network address translator (Traditional NAT). RFC 3022 (Informational).   Srisuresh P. and Egevang K. 2001. Traditional IP network address translator (Traditional NAT). RFC 3022 (Informational).","DOI":"10.17487\/rfc3022"},{"key":"e_1_2_1_59_1","unstructured":"The Open Web Application Security Project (OWASP). 2010. OWASP Top 10 for 2010. http:\/\/owasptop10.googlecode.com\/files\/OWASP&percnt;20Top&percnt;2010&percnt;20-&percnt;202010.pdf.  The Open Web Application Security Project (OWASP). 2010. OWASP Top 10 for 2010. http:\/\/owasptop10.googlecode.com\/files\/OWASP&percnt;20Top&percnt;2010&percnt;20-&percnt;202010.pdf."},{"key":"e_1_2_1_60_1","unstructured":"Zalewski M. 2001. Strange attractors and TCP\/IP sequence number analysis. http:\/\/lcamtuf.coredump.cx\/newtcp\/.  Zalewski M. 2001. Strange attractors and TCP\/IP sequence number analysis. http:\/\/lcamtuf.coredump.cx\/newtcp\/."},{"key":"e_1_2_1_61_1","unstructured":"Zalewski M. 2003. A new TCP\/IP blind data injection technique? BugTraq mailing list post. http:\/\/lcamtuf.coredump.cx\/ipfrag.txt.  Zalewski M. 2003. A new TCP\/IP blind data injection technique? BugTraq mailing list post. http:\/\/lcamtuf.coredump.cx\/ipfrag.txt."},{"key":"e_1_2_1_62_1","unstructured":"Zalewski M. 2005. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks. No Starch Press.   Zalewski M. 2005. Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks . No Starch Press."}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2445566.2445568","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2445566.2445568","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:34:09Z","timestamp":1750239249000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2445566.2445568"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,4]]},"references-count":62,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,4]]}},"alternative-id":["10.1145\/2445566.2445568"],"URL":"https:\/\/doi.org\/10.1145\/2445566.2445568","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,4]]},"assertion":[{"value":"2012-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2012-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-04-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}