Using abnormal TTL values to detect malicious IP packets

Ryo Yamada, Shegeki Goto · Proceedings of the Asia-Pacific Advanced Network · 2012

Abstract: In general, an IP packet passes through less than 30 routers before it reaches a destination host. According to our observations, some IP packets have an abnormal time-to-live (TTL) value that is decreased by more than 30 increments from the initial TTL. These packets are likely to be generated by special software. We assume that IP packets with strange TTL values are malicious. This study investigates this conjecture through several experiments, and the results show that malicious packets can be discriminated from legitimate ones by observing only TTL values.

Read the paper · More papers on PaperTik