USENIX Security2026Top-tier venue
FRAGJAM: DoS Attacks Using IP Reassembly Congestion
Yepeng Pan, Christian Rossow
Abstract
UDP, one of the major transport protocols for multiple popular services such as DNS and video conferencing, is an important component of today's network. Its reliance on IP fragmentation is known to cause both security and reliability issues. To avoid fragmentation, UDP-based applications hence usually limit the payload size. Currently, Linux's IP fragment reassembling algorithm relies on a per-network-namespace buffer size limit. That is, a classic resource-exhaustion DoS attack against UDP services relying on IP fragmentation is possible. However, the fragility of present real-world services has not yet been thoroughly researched. In this paper, we examine the practicability of such an IP-fragmentation-based DoS attack against real-world providers of popular UDP-based services, including VPN, video conferencing, and RADIUS. We assess the attack from both the client and service provider perspectives. On the server side, we observe that many real-world service providers fragment the server-to-client traffic with respect to artificially small path MTUs when receiving attacker forged ICMP Fragmentation Needed messages. On the client side, we show the chance of dropping server-to-client fragmented traffic by flooding Linux-based NAT gateways with bogus fragments. Through simulated attacks, we demonstrate that the fragmentation-based DoS attack is realistic, affecting various providers such as Zoom and ExpressVPN. We conduct a comprehensive disclosure to affected parties and suggest possible mitigations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- Domain Validation++ For MitM-Resilient PKIMarkus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann et al.CCS 2018 · 71 citations
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 33 citations
- Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect AttacksXuewei Feng, Qi Li, Kun Sun, Zhiyun Qian et al.USENIX Security 2022
- Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding DevicesXiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang et al.USENIX Security 2020
Related papers
- PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCPXuewei Feng, Qi Li, Kun Sun, Ke Xu et al.NDSS 2022
- Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on LinuxDashuai Wu, Yunyi Zhang, Baojun Liu, Xiang Li et al.CCS 2025
- Evaluating Susceptibility of VPN Implementations to DoS Attacks Using Adversarial TestingFabio Streun, Joel Wanner, Adrian PerrigNDSS 2022
- ReDAN: An Empirical Study on Remote DoS Attacks against NAT NetworksXuewei Feng, Yuxiang Yang, Qi Li, Xingxiang Zhan et al.NDSS 2025
- Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNsYuxiang Yang, Ao Wang, Xuewei Feng, Qi Li et al.INFOCOM 2026 · 1 citation
