What happens if a packet is not received within a reasonable period during session splicing?

Study for the EC-Council Certified Ethical Hacker (CEH) v13 Exam. Utilize flashcards and multiple-choice questions with helpful hints and detailed explanations. Excel in your exam preparation!

Multiple Choice

What happens if a packet is not received within a reasonable period during session splicing?

Explanation:
During session splicing, a transmitter tries to break a single session into pieces to defeat how an IDS reconstructs traffic. Stateful IDS monitor per-session state and hold reassembly buffers for a window of time. If a packet for that session doesn’t arrive within a reasonable period, the IDS will time out and discard the partial reassembly, stopping any further attempt to reassemble that stream. This prevents resources from being tied up on an incomplete session and means the IDS will not reassemble or inspect that portion of traffic. That’s why the best description is that many IDS stop reassembling and handling that communication stream. The other options don’t fit because timing out doesn’t cause a protocol switch, immediate attacker logging isn’t guaranteed by this behavior, and the IDS isn’t forced to continue reassembling regardless of timing.

During session splicing, a transmitter tries to break a single session into pieces to defeat how an IDS reconstructs traffic. Stateful IDS monitor per-session state and hold reassembly buffers for a window of time. If a packet for that session doesn’t arrive within a reasonable period, the IDS will time out and discard the partial reassembly, stopping any further attempt to reassemble that stream. This prevents resources from being tied up on an incomplete session and means the IDS will not reassemble or inspect that portion of traffic.

That’s why the best description is that many IDS stop reassembling and handling that communication stream. The other options don’t fit because timing out doesn’t cause a protocol switch, immediate attacker logging isn’t guaranteed by this behavior, and the IDS isn’t forced to continue reassembling regardless of timing.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy