Defending against Sequence Number Attacks
RFC 6528, “Defending against Sequence Number Attacks”, is a Proposed Standard document published in February 2012 by F. Gont, S. Bellovin. It updates RFC 793. It obsoletes RFC 1948. It has been obsoleted by RFC 9293 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document specifies an algorithm for the generation of TCP Initial Sequence Numbers (ISNs), such that the chances of an off-path attacker guessing the sequence numbers in use by a target connection are reduced. This document revises (and formally obsoletes) RFC 1948, and takes the ISN generation algorithm originally proposed in that document to Standards Track, formally updating RFC 793. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6528 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6527 Definitions of Managed Objects for Virtual Router Redundancy Protocol Version 3
- RFC 6529 Host/Host Protocol for the ARPA Network
- RFC 6526 IP Flow Information Export Per Stream Control Transmission Protocol Stream
- RFC 6530 Overview and Framework for Internationalized Email
- RFC 6525 Stream Control Transmission Protocol Stream Reconfiguration
- RFC 6531 SMTP Extension for Internationalized Email
- RFC 6532 Internationalized Email Headers
- RFC 6533 Internationalized Delivery Status and Disposition Notifications