Network Working Group S. Bellovin
Request for Comments: 1948 AT&T Research
Category: Informational May 1996
Defending Against Sequence Number Attacks
Bellovin Informational [Page 1]
RFC 1948 Sequence Number Attacks May 1996
Details of the Attack
Bellovin Informational [Page 2]
RFC 1948 Sequence Number Attacks May 1996
goes to the legitimate A, about which more anon. X never sees that message but can still send
Bellovin Informational [Page 3]
RFC 1948 Sequence Number Attacks May 1996
It is vital that F not be computable from the outside, or an attacker could still guess at sequence numbers from the initial sequence number used for some other connection. We therefore suggest that F be a cryptographic hash function of the connection-id and some secret data. MD5 [9] is a good choice, since the code is widely available. The secret data can either be a true random number [10], or it can be the combination of some per-host secret and the boot time of the machine. The boot time is included to ensure that the secret is changed on occasion. Other data, such as the host's IP address and name, may be included in the hash as well; this eases administration by permitting a network of workstations to share the same secret data while still giving them separate sequence number spaces. Our recommendation, in fact, is to use all three of these items: as random a number as the hardware can generate, an administratively- installed pass phrase, and the machine's IP address. This allows for local choice on how secure the secret is.
Bellovin Informational [Page 4]
RFC 1948 Sequence Number Attacks May 1996
Security Considerations
Bellovin Informational [Page 5]
RFC 1948 Sequence Number Attacks May 1996
[5] Postel, J., and J. Reynolds, "Telnet Protocol Specification",