Jump to content

Packet injection

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Citation bot (talk | contribs) at 22:07, 21 November 2021 (Add: date, title. Changed bare reference to CS1/2. | Use this bot. Report bugs. | Suggested by BrownHairedGirl | Linked from User:BrownHairedGirl/Articles_with_bare_links | #UCB_webform_linked 2057/2197). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Packet injection (also known as forging packets or spoofing packets) in computer networking, is the process of interfering with an established network connection by means of constructing packets to appear as if they are part of the normal communication stream. The packet injection process allows an unknown third party to disrupt or intercept packets from the consenting parties that are communicating, which can lead to degradation or blockage of users' ability to utilize certain network services or protocols. Packet injection is commonly used in man-in-the-middle attacks and denial-of-service attacks.

Capabilities

By utilizing raw sockets, NDIS function calls, or direct access to a network adapter kernel mode driver, arbitrary packets can be constructed and injected into a computer network. These arbitrary packets can be constructed from any type of packet protocol (ICMP, TCP, UDP, and others) since there is full control over the packet header while the packet is being assembled.

General procedure

Uses

Packet injection has been used for:

Detecting packet injection

Through the process of running a packet analyzer or packet sniffer on both network service access points trying to establish communication, the results can be compared. If point A has no record of sending certain packets that show up in the log at point B, and vice versa, then the packet log inconsistencies show that those packets have been forged and injected by an intermediary access point. Usually TCP resets are sent to both access points to disrupt communication.[2][3][4]

Software

See also

References

  1. ^ http://s2.ist.psu.edu/paper/cross-TR.pdf
  2. ^ a b "Packet Forgery by ISPs: A Report on the Comcast Affair". 28 November 2007.
  3. ^ "Detecting packet injection: A guide to observing packet spoofing by ISPs". 27 November 2007.
  4. ^ http://www.icir.org/vern/papers/reset-injection.ndss09.pdf