PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

How could this be done?

By manipulating the TTL on a TCP packet, an attacker could desynchronize inspection. Signature
1308 (TTL evasion) fires when the TTL for any packet in a TCP session is higher than the lowestobserved TTL for that session. Signature 1308 rewrites all TTLs to the lowest-observed TTL, and
produces an alert. You would like to have the signature continue to modify packets inline but avoid
generating alerts.
How could this be done?