• Open Daily: 10am - 10pm
    Alley-side Pickup: 10am - 7pm

    3038 Hennepin Ave Minneapolis, MN
    612-822-4611

Open Daily: 10am - 10pm | Alley-side Pickup: 10am - 7pm
3038 Hennepin Ave Minneapolis, MN
612-822-4611
TCP/IP in Practice: Reconnaissance, Fingerprinting, and the Defenses That Answer Them

TCP/IP in Practice: Reconnaissance, Fingerprinting, and the Defenses That Answer Them

Paperback

Series: In Practice

Computer Security

Currently unavailable to order

ISBN13: 9798170832286
Publisher: Independently Published
Pages: 152
Weight: 0.42
Height: 0.38 Width: 6.00 Depth: 9.00
Language: English
You can run traceroute. Can you explain why it works?

Every networking tool is applied protocol semantics. It repurposes a field, or exploits a behavior the RFC either mandated or left undefined. Traceroute is the TTL field doing a second job. The nmap SYN, FIN, NULL, Xmas, and ACK scans are RFC 793's own mandated replies turned into a probe. The idle scan reads a stranger's IP ID counter. p0f fingerprints a host from the idiosyncrasies of its TCP options. The Kaminsky attack races sixteen bits of DNS entropy.

TCP/IP in Practice teaches the stack the way an engineer actually learns it: by understanding why each tool works, field by field, and then inverting every mechanism into a defense.

For each technique, the book shows the defensive inversion the protocol community actually shipped - SYN cookies, GTSM, RFC 6528 sequence numbers, source-port randomization, DNS 0x20 encoding, response-rate limiting, and uRPF - as one coherent family rather than a list of unrelated fixes.

Who it is for

Also in

Computer Security