FINDING · DEFENSE

TCP RSTs are delivered unreliably and different OS stacks apply different validity rules, so a NIDS cannot safely tear down connection state on RST alone; a 'reliable RST' scheme — sending a keep-alive ACK behind every forwarded RST and tearing down state only upon observing a confirming RST from the trusted side — resolves this without violating end-to-end semantics. The cold-start problem (state loss on restart) can be addressed statelessly by stripping payload from unknown-connection packets from untrusted hosts and probing the trusted endpoint with a keep-alive before instantiating state.

From 2001-handley-networkNetwork Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics · §6.1–6.2 · 2001 · USENIX Security Symposium

Implications

Tags

techniques
middlebox-interferencerst-injection
defenses
meta-resistance

Extracted by claude-sonnet-4-6 — review before relying.