FINDING · EVALUATION

Middleboxes that randomize TCP sequence numbers do not update the sequence numbers inside TCP SACK blocks; tracebox found two PlanetLab VPs with stateful seq-number randomizers that cycled approximately every 20 seconds. When SACK blocks reference sequence numbers outside the current window, the Linux TCP stack waits for a full RTO instead of fast-retransmitting, producing up to 50% throughput degradation in controlled measurements.

From 2013-detal-revealingRevealing Middlebox Interference with Tracebox · §3.3 · 2013 · Internet Measurement Conference

Implications

Tags

censors
generic
techniques
middlebox-interference

Extracted by claude-sonnet-4-6 — review before relying.