PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
Xuewei Feng, Qi Li, Kun Sun, Ke Xu, Baojun Liu, Xiaofeng Zheng, Qiushi Yang, Haixin Duan, Zhiyun Qian
Abstract
—There is a widespread belief that TCP is not vulner- able to IP fragmentation attacks since TCP performs the Path Maximum Transmission Unit Discovery (PMTUD) mechanism by default, which can avoid IP fragmentation by dynamically matching the maximum size of TCP segments with the maximum transmission unit (MTU) of the path from the originator to the destination. However, this paper reveals that TCP is in fact vulnerable to IP fragmentation attacks, which is contrary to the common belief. We conduct a systematic study on the complex interactions between IP fragmentation and TCP, and we discover two key situations under which IP fragmentation can still be triggered on TCP segments even if the originator performs PMTUD. First, when the next-hop MTU of an intermediate router is smaller than the originator’s acceptable minimum path MTU, TCP segments from the originator will be fragmented by the router. Second, when the originator’s path MTU values between the IP layer and the TCP layer are desynchronized due to a maliciously crafted ICMP error message, the originator could be tricked into fragmenting TCP segments. Once IP fragmentation on TCP segments could be falsely triggered, attackers can inject forged fragments into the victim connection to poison the target TCP traffic after successfully addressing practical issues of predicting IPID and deceiving TCP checksum. Our case studies on both HTTP and BGP demonstrate the feasibility and effectiveness of poisoning TCP-based applications via IP fragmentation. We also conduct a comprehensive evaluation to show that our attacks can cause serious damages in the real world. Finally, we propose countermeasures to mitigate malicious IP fragmentation on TCP segments and defeat the attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
- Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph AnalysisChuanpu Fu, Qi Li, Ke XuNDSS 2023
- Athena: Analyzing and Quantifying Side Channels of Transport Layer ProtocolsFeiyang Yu, Quan Zhou, Syed Rafiul Hussain, Danfeng ZhangUSENIX Security 2024
- FRAGJAM: DoS Attacks Using IP Reassembly CongestionYepeng Pan, Christian RossowUSENIX Security 2026
- Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing ScenariosXuewei Feng, Zhaoxi Li, Qi Li, Ziqiang Wang et al.CCS 2025
Builds on15
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- The use of TLS in Censorship CircumventionSergey Frolov, Eric WustrowNDSS 2019 · 97 citations
- End-to-End Measurements of Email Spoofing AttacksHang Hu, Gang WangUSENIX Security 2018 · 94 citations
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys et al.CCS 2019 · 89 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
Related papers
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun et al.CCS 2020 · 39 citations
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- ReDAN: An Empirical Study on Remote DoS Attacks against NAT NetworksXuewei Feng, Yuxiang Yang, Qi Li, Xingxiang Zhan et al.NDSS 2025
- Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi NetworksYuxiang Yang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2024
- Automated Attack Discovery in TCP Congestion Control Using a Model-guided ApproachSamuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove et al.NDSS 2018 · 46 citations
