Although the Transmission Control Protocol (TCP) constitutes the foundation of reliable communication on the Internet, it was designed in the 1970s under an assumption of implicit trust among nodes, devoid of native authentication, integrity, and confidentiality mechanisms. This thesis analyzes, from both a theoretical and experimental perspective, three classes of vulnerabilities that exploit this lack of structural security: SYN Flooding, the TCP Reset Attack, and TCP Session Hijacking. After reviewing the protocol architecture and the Three-Way Handshake mechanism, the work explores SYN Flooding, which exploits the finite capacity of the half-open connection queue; it then examines its primary countermeasure, SYN Cookies, supported by a Mininet testbed evaluated across three comparative experimental scenarios. Next, the TCP Reset Attack is investigated by distinguishing between on-path and off-path scenarios, including practical validation based on the automated disruption of a streaming flow via sniff-and-spoof techniques. Finally, Session Hijacking is analyzed, beginning with packet injection constraints (4-tuple matching and Sequence Number alignment) through to high-impact scenarios such as session desynchronization and remote command execution via reverse shell. The thesis concludes with a comparative evaluation of key countermeasures (SYN Proxy, RFC 5961, and NIDS systems) and reflects on the evolution of transport protocols toward QUIC, which natively incorporates encryption and authentication from the very first exchanged packet. This study demonstrates that historical TCP defenses represent retrofitted patches rather than architectural solutions, underscoring the imperative for a security-by-design approach in network protocol engineering.
Il protocollo TCP (Transmission Control Protocol), pur costituendo il fondamento della comunicazione affidabile su Internet, è stato progettato negli anni '70 in un contesto di fiducia implicita tra i nodi, privo di meccanismi nativi di autenticazione, integrità e riservatezza. Questa tesi analizza, dal punto di vista sia teorico sia sperimentale, tre classi di vulnerabilità che sfruttano tale assenza di sicurezza strutturale: il SYN Flooding, il TCP Reset Attack e il TCP Session Hijacking. Dopo aver richiamato l'architettura del protocollo e il meccanismo del Three-Way Handshake, viene approfondito il SYN Flooding, che sfrutta la capienza finita della coda delle connessioni half-open; successivamente viene analizzata la relativa contromisura, i SYN Cookies, e viene eseguito un testbed Mininet attraverso tre scenari sperimentali comparativi. Poi il TCP Reset Attack viene esaminato distinguendo gli scenari on-path e off-path, con una validazione pratica basata sull'interruzione automatizzata di un flusso di streaming tramite tecniche di sniff-and-spoof. Infine, il Session Hijacking viene analizzato a partire dai vincoli di iniezione (corrispondenza della quadrupla e allineamento del Sequence Number), fino agli scenari di impatto più critici, quali la desincronizzazione della sessione e l'esecuzione di comandi remoti tramite reverse shell. Il lavoro si conclude con un'analisi comparativa delle principali contromisure (SYN Proxy, RFC 5961, sistemi NIDS) e con una riflessione sull'evoluzione dei protocolli di trasporto verso QUIC, che integra cifratura e autenticazione fin dal primo pacchetto scambiato. L'elaborato mostra come le difese storiche del TCP costituiscano correttivi a posteriori piuttosto che soluzioni strutturali, sostenendo la necessità di un approccio di sicurezza nativo (security by design) nella progettazione dei protocolli di rete.
Sicurezza del protocollo TCP: implicazioni, vettori di attacco e stato dell'arte
DUAN, JIANBIN
2025/2026
Abstract
Although the Transmission Control Protocol (TCP) constitutes the foundation of reliable communication on the Internet, it was designed in the 1970s under an assumption of implicit trust among nodes, devoid of native authentication, integrity, and confidentiality mechanisms. This thesis analyzes, from both a theoretical and experimental perspective, three classes of vulnerabilities that exploit this lack of structural security: SYN Flooding, the TCP Reset Attack, and TCP Session Hijacking. After reviewing the protocol architecture and the Three-Way Handshake mechanism, the work explores SYN Flooding, which exploits the finite capacity of the half-open connection queue; it then examines its primary countermeasure, SYN Cookies, supported by a Mininet testbed evaluated across three comparative experimental scenarios. Next, the TCP Reset Attack is investigated by distinguishing between on-path and off-path scenarios, including practical validation based on the automated disruption of a streaming flow via sniff-and-spoof techniques. Finally, Session Hijacking is analyzed, beginning with packet injection constraints (4-tuple matching and Sequence Number alignment) through to high-impact scenarios such as session desynchronization and remote command execution via reverse shell. The thesis concludes with a comparative evaluation of key countermeasures (SYN Proxy, RFC 5961, and NIDS systems) and reflects on the evolution of transport protocols toward QUIC, which natively incorporates encryption and authentication from the very first exchanged packet. This study demonstrates that historical TCP defenses represent retrofitted patches rather than architectural solutions, underscoring the imperative for a security-by-design approach in network protocol engineering.| File | Dimensione | Formato | |
|---|---|---|---|
|
Duan_Jianbin.pdf
accesso aperto
Dimensione
345.98 kB
Formato
Adobe PDF
|
345.98 kB | Adobe PDF | Visualizza/Apri |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/114202