ICMP: an Attack Vector against IPsec Gateways

In this work we show that the Internet Control Message Protocol (ICMP) can be used as an attack vector against IPsec gateways. The main contribution of this work is to demonstrate that an attacker having eavesdropping and traffic injection capabilities in the black untrusted network (he only sees ciphered packets), can force a gateway to reduce the Path MTU of an IPsec tunnel to a minimum, which in turn creates serious issues for devices on the trusted network behind this gateway: depending on the Path MTU discovery algorithm, it either prevents any new TCP connection (Denial of Service), or it creates major performance penalties (more than 6 seconds of delay in TCP connection establishment and ridiculously small TCP segment sizes). After detailing the attack and the behavior of the various nodes, we discuss some counter measures, with the goal to find a balance between ICMP benefits and the associated risks.

Data and Resources

Additional Info

Field Value
Source https://inria.hal.science/hal-00879997
Author Jacquin, Ludovic, Roca, Vincent, Roch, Jean-Louis
Maintainer CCSD
Last Updated May 9, 2026, 03:40 (UTC)
Created May 9, 2026, 03:40 (UTC)
Identifier hal-00879997
Language en
Rights https://about.hal.science/hal-authorisation-v1/
contributor Privacy Models, Architectures and Tools for the Information Society (PRIVATICS) ; Centre Inria de l'Université Grenoble Alpes ; Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National de Recherche en Informatique et en Automatique (Inria)-CITI Centre of Innovation in Telecommunications and Integration of services (CITI) ; Institut National des Sciences Appliquées de Lyon (INSA Lyon) ; Université de Lyon-Institut National des Sciences Appliquées (INSA)-Université de Lyon-Institut National des Sciences Appliquées (INSA)-Institut National de Recherche en Informatique et en Automatique (Inria)-Institut National des Sciences Appliquées de Lyon (INSA Lyon) ; Université de Lyon-Institut National des Sciences Appliquées (INSA)-Université de Lyon-Institut National des Sciences Appliquées (INSA)-Centre Inria de Lyon ; Institut National de Recherche en Informatique et en Automatique (Inria)
creator Jacquin, Ludovic
date 2013-10-09T00:00:00
harvest_object_id c5de2f52-6748-4302-b3fb-aedaf8cdea20
harvest_source_id 3374d638-d20b-4672-ba96-a23232d55657
harvest_source_title test moissonnage SELUNE
metadata_modified 2025-09-27T00:00:00
set_spec type:UNDEFINED