Layer 4 - Transport¶
The transport layer. TCP and UDP carry the sessions; their state machines and the absence of authentication enable scanning, flooding, hijacking and evasion of the sensors watching them.
Modules¶
- Port scanning & fingerprinting - Scanning techniques and TCP/IP stack fingerprinting. (
netlab-portscan) - TCP SYN flood - Exhaust the connection table with half-open connections. (
netlab-synflood) - TCP session hijacking - Inject into / reset an established TCP session. (
netlab-tcphijack) - Reflection & amplification - Measure the amplification factor (DNS/NTP/memcached) in-lab. (
netlab-amplif) - NIDS evasion (insertion/evasion) ⭐ - Ptacek-Newsham techniques: insertion/evasion, TCP desync - flagship. (
netlab-ids-evasion) - Covert channels - Generic covert channels in header fields and timing. (
netlab-covert)