RFC 1948: Defending Against Sequence Number Attacks
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 6528.
Current document in this lineage: RFC 7805 — Moving Outdated TCP Extensions and TCP-Related Documents to Historic or Informational Status; RFC 9293 — Transmission Control Protocol (TCP)
In plain English — editorial summary, not part of the RFC
IP spoofing attacks based on sequence number spoofing have become a serious threat on the Internet (CERT Advisory CA-95:01). While ubiquitous crypgraphic authentication is the right answer, we propose a simple modification to TCP implementations that should be a very substantial block to the current wave of attacks. This memo provides information for the Internet community. This memo does not specify an Internet standard of any kind.
Document record
- Document ID
- RFC1948
- Published
- May 1996
- Authors
- S. Bellovin
- Status
- INFORMATIONAL
- Stream
- Legacy
- Area
- —
- Pages
- 6
- Also known as
- —
- Obsoleted by:
- RFC 6528
Topics
Standards lineage
This document is one revision in a chain of 18 RFCs, each formally replacing the one before it.
- RFC 675 (1974)
- RFC 721 (1976)
- RFC 761 (1980)
- RFC 793 (1981)
- RFC 813 (1982)
- RFC 816 (1982)
- RFC 879 (1983)
- RFC 896 (1984)
- RFC 1078 (1988)
- RFC 1948 (1996)
- RFC 2873 (2000)
- RFC 6013 (2011)
- RFC 6093 (2011)
- RFC 6429 (2011)
- RFC 6528 (2012)
- RFC 6691 (2012)
- RFC 7805 (2016)
- RFC 9293 (2022) ✓
Read the full history of Transmission Control Protocol (TCP) →
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 4871DomainKeys Identified Mail (DKIM) SignaturesObsoleted
May 2007
- RFC 6651Extensions to DomainKeys Identified Mail (DKIM) for Failure ReportingCurrent
June 2012
- RFC 7208Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1Updated
April 2014
- RFC 2015MIME Security with Pretty Good Privacy (PGP)Updated
October 1996
- RFC 1810Report on MD5 PerformanceCurrent
June 1995
- RFC 2107Ascend Tunnel Management Protocol - ATMPCurrent
February 1997
- RFC 2139RADIUS AccountingObsoleted
April 1997
- RFC 2286Test Cases for HMAC-RIPEMD160 and HMAC-RIPEMD128Current
February 1998
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?