RFC 9416: Security Considerations for Transient Numeric Identifiers Employed in Network Protocols
In plain English — editorial summary, not part of the RFC
Poor selection of transient numerical identifiers in protocols such as the TCP/IP suite has historically led to a number of attacks on implementations, ranging from Denial of Service (DoS) or data injection to information leakages that can be exploited by pervasive monitoring. Due diligence in the specification of transient numeric identifiers is required even when cryptographic techniques are employed, since these techniques might not mitigate all the associated issues. This document formally updates RFC 3552, incorporating requirements for transient numeric identifiers, to prevent flaws in future protocols and implementations.
Document record
- Document ID
- RFC9416
- Published
- July 2023
- Authors
- F. Gont; I. Arce
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- —
- Pages
- 10
- Also known as
- BCP72
- Updates:
- RFC 3552
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9415On the Generation of Transient Numeric IdentifiersCurrent
July 2023
- RFC 9414Unfortunate History of Transient Numeric IdentifiersCurrent
July 2023
- RFC 7739Security Implications of Predictable Fragment Identification ValuesCurrent
February 2016
- RFC 5961Improving TCP's Robustness to Blind In-Window AttacksUpdated
August 2010
- RFC 7943A Method for Generating Semantically Opaque Interface Identifiers (IIDs) with the Dynamic Host Configuration Protocol for IPv6 (DHCPv6)Current
September 2016
- RFC 9396OAuth 2.0 Rich Authorization RequestsCurrent
May 2023
- RFC 9449OAuth 2.0 Demonstrating Proof of Possession (DPoP)Current
September 2023
- RFC 9456Updates to the TLS Transport Model for SNMPCurrent
November 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?