IO

I.C. Oprea

2 records found

Lost in Reassembly: Exploiting IP Fragmentation in Computer Networks

An Experimental Security Evaluation of Fragmentation Handling, Detection Limitations, and Attack Scenarios

IPv6 fragmentation remains a subtle yet impactful security concern in modern high-throughput, low-latency networks, where packet inspection is constrained by performance requirements and out-of-path monitoring architectures. This thesis investigates how discrepancies in IPv6 frag ...

Investigating the impact of PDFA implementation on alert-driven attack graphs

A comparison between the Suffix-based PDFA and PDFA models

SAGE is a deterministic and unsupervised learning pipeline that can generate attack graphs from intrusion alerts without input knowledge from a security analyst. Using a suffix-based probabilistic deterministic finite automaton (S-PDFA), the system compresses over 1 million alert ...