Packet (network) in the context of TCP sequence prediction attack


Packet (network) in the context of TCP sequence prediction attack

Packet (network) Study page number 1 of 1

Play TriviaQuestions Online!

or

Skip to study material about Packet (network) in the context of "TCP sequence prediction attack"


HINT:

👉 Packet (network) in the context of TCP sequence prediction attack

A TCP sequence prediction attack is an attempt to predict the sequence number used to identify the packets in a TCP connection, which can be used to counterfeit packets.

The attacker hopes to correctly guess the sequence number to be used by the sending host. If they can do this, they will be able to send counterfeit packets to the receiving host which will seem to originate from the sending host, even though the counterfeit packets may in fact originate from some third host controlled by the attacker. One possible way for this to occur is for the attacker to listen to the conversation occurring between the trusted hosts, and then to issue packets using the same source IP address. By monitoring the traffic before an attack is mounted, the malicious host can figure out the correct sequence number. After the IP address and the correct sequence number are known, it is basically a race between the attacker and the trusted host to get the correct packet sent. One common way for the attacker to send it first is to launch another attack on the trusted host, such as a denial-of-service attack. Once the attacker has control over the connection, they are able to send counterfeit packets without getting a response.

↓ Explore More Topics
In this Dossier