database logo graphic

RFC 6528

"Defending against Sequence Number Attacks", February 2012

Canonical URL:
http://www.rfc-editor.org/rfc/rfc6528.txt
This document is also available in this non-normative format: PDF.
Status:
PROPOSED STANDARD
Obsoletes:
RFC 1948
Updates:
RFC 793
Authors:
F. Gont
S. Bellovin
Stream:
IETF
Source:
tcpm (tsv)

Please refer here for any errata for this document. To submit a new errata report, go to the main errata page.


Abstract

This document specifies an algorithm for the generation of TCP Initial Sequence Numbers (ISNs), such that the chances of an off-path attacker guessing the sequence numbers in use by a target connection are reduced. This document revises (and formally obsoletes) RFC 1948, and takes the ISN generation algorithm originally proposed in that document to Standards Track, formally updating RFC 793. [STANDARDS-TRACK]


For the definition of Status, see RFC 2026.

For the definition of Stream, see RFC 4844.


Go to the RFC Editor Homepage.