Abstract
PurposeThis study seeks to investigate modern internet back‐bone traffic in order to study occurrences of malicious activities and potential security problems within internet packet headers.Design/methodology/approachContemporary and highly aggregated back‐bone data have been analyzed regarding consistency of network and transport layer headers (i.e. IP, TCP, UDP and ICMP). Possible security implications of each anomaly observed are discussed.FindingsA systematic listing of packet header anomalies, together with their frequencies as seen “in the wild”, is provided. Inconsistencies in protocol headers have been found within almost every aspect analyzed, including incorrect or incomplete series of IP fragments, IP address anomalies and other kinds of header fields not following internet standards. Internet traffic was shown to contain many erroneous packets; some are the result of software and hardware errors, others the result of intentional and malicious activities.Practical implicationsThe study not only presents occurrences of header anomalies as observed in today's internet traffic, but also provides detailed discussions about possible causes for the inconsistencies and their security implications for networked devices.Originality/valueThe results are relevant for researchers as well as practitioners, and form a valuable input for intrusion detection systems, firewalls and the design of all kinds of networked applications exposed to network attacks.
Talk to us
Join us for a 30 min session where you can share your feedback and ask us any queries you have
Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.