IP Fragmentation Evasion Testing for Network Security Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices struggle to effectively identify and block malicious IP packets that employ fragmentation evasion techniques, such as fragmentation, reordering, duplication, null insertion, and overlap, which can confuse these devices and allow malicious traffic to pass through.
Innovation Solution
A system and method for combining IP fragmentation evasion techniques, including a packet network test device that generates and fragments IP packets, applies multiple evasion techniques, and transmits the resulting fragments to a device under test, allowing users to select and order the techniques to simulate various attack scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network security devices use traditional packet inspection methods, then they can identify simple malicious packets, but they become confused and unable to properly identify packets that are fragmented and reordered
Solution Approach 1:
The patent segments the malicious payload into multiple IP fragments and applies different evasion techniques to each fragment. The test device divides the original packet into fragments that can be reordered, duplicated, or nullified independently, allowing comprehensive testing of security devices' ability to handle fragmented malicious traffic
Solution Approach 2:
The patent nests multiple evasion techniques within a single test scenario. Fragmentation evasion techniques are nested within reordering techniques, which are nested within duplication techniques, creating layered attack scenarios that test security devices against combined evasion methods
2Object-affected harmful factors
If sources of malicious traffic use IP fragmentation evasion techniques, then malicious packets can pass through security devices, but security devices lack the ability to robustly handle all possible combinations of these techniques
Solution Approach 1:
The patent implements feedback mechanisms where the test device monitors how security devices handle fragmented packets and adjusts subsequent test scenarios based on observed vulnerabilities. The system learns from each test outcome and refines its evasion technique combinations to更全面地 test security device robustness
Solution Approach 2:
The patent systematically changes parameters such as fragment size, overlap程度, reordering patterns, and duplication rates to create diverse test scenarios. By varying these parameters across multiple test runs, the system evaluates security device reliability under different fragmentation evasion conditions
3Object-affected harmful factors
If security devices block all fragmented packets to prevent evasion, then malicious traffic is blocked, but legitimate fragmented packets are also blocked causing loss of normal traffic
Solution Approach 1:
The patent applies partial fragmentation evasion techniques where only certain fragments are reordered or duplicated while others maintain normal sequence. This allows testing of security devices' ability to distinguish between malicious partial fragmentation and legitimate complete fragmentation, reducing false positives
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, and computer readable media for combining IP fragmentation evasion techniques are disclosed. According to one aspect, the subject matter described herein includes a method for combining IP fragmentation evasion techniques. In a packet network test device, a plurality of IP fragmentation evasion techniques are defined. An IP packet is generated and fragmented into a first set of IP packet fragments. To the first set of IP packet fragments, each of the multiple IP fragmentation evasion techniques are applied. This produces a second set of IP packet fragments, which are transmitted to the device under test.