Detecting Forged TCP Reset Packets.

Nicholas C. Weaver, Robin Sommer, Vern Paxson · 2009

Several off-the-shelf products enable network operators to enforce usage restrictions by actively terminating connections when deemed undesirable. While the spectrum of their application is large—from ISPs limiting the usage of P2P applications to the “Great Firewall of China”—many of these systems implement the same approach to disrupt the communication: they inject artificial TCP Reset (RST) packets into the network, causing the endpoints to shut down communication upon receipt. In this work, we study the characteristics of packets injected by such traffic controldevices. Weshowthatbyexploitingtherace-conditions that out-of-band devices inevitably face, we not only can detect the interference but often also fingerprint the specificdeviceinuse. Wedevelopanefficientinjectiondetector and demonstrate its effectiveness by identifying a range of disruptive activity seen in traces from four different sites, including termination of P2P connections, anti-spam and anti-virusmechanisms,andthefindingthatChina’s“Great Firewall ” has multiple components, sometimes apparently operating without coordination. We also find a number of sources of idiosyncratic connection termination that do not reflect third-party traffic disruption, including NATs, loadbalancers,andspambots. Ingeneral,ourfindingshighlight that (i)Internettrafficfacesawiderangeofcontroldevices using injected RST packets, and (ii) to reliably detect RST injection while avoiding misidentification of other types of activity requires significant care. 1

Read the paper · More papers on PaperTik