FINDING · DETECTION

Passive NIDS can be evaded via three fundamental classes of ambiguity: incomplete protocol analysis (none of the four commercial systems tested by Ptacek and Newsham in 1998 correctly reassembled IP fragments), divergent end-system behavior (different OS stacks resolve overlapping TCP retransmissions differently), and topology uncertainty (low-TTL packets may not reach the victim end-system, so the NIDS cannot determine which packets are delivered).

From 2001-handley-networkNetwork Intrusion Detection: Evasion, Traffic Normalization, and End-to-End Protocol Semantics · §1 · 2001 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dpimiddlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.