ietf-corpus

rfc-9416

Security Considerations for Transient Numeric Identifiers Employed in Network Protocols

F. Gont, I. Arce
date2023-07 streamIETF wgnon working group statusBEST CURRENT PRACTICE pages10 canonicalhttps://www.rfc-editor.org/rfc/rfc9416 doi10.17487/RFC9416
Poor selection of transient numerical identifiers in protocols such as the TCP/IP suite has historically led to a number of attacks on implementations, ranging from Denial of Service (DoS) or data injection to information leakages that can be exploited by pervasive monitoring. Due diligence in the specification of transient numeric identifiers is required even when cryptographic techniques are employed, since these techniques might not mitigate all the associated issues. This document formally updates RFC 3552, incorporating requirements for transient numeric identifiers, to prevent flaws in future protocols and implementations.

updates

also