DeepSec 2025 Talk: From Firewalls to Fragmentation: Identifying Adversarial Traffic in a Politically Divided Internet – Vladimer Svanadze

Sanna/ October 8, 2025/ Conference/ 0 comments

This talk presents a multidimensional analysis of Internet fragmentation, examining how political, technical, economic and cybersecurity factors are converging to break apart the global Internet. While often viewed through a policy lens, fragmentation has real-world implications at the packet level. We introduce a lightweight, rule-based detection model capable of identifying fragmented, mis-configured and adversarial IP/UDP traffic. Built upon RFC 791 semantics, the model analyzes packet offset alignment, TTL discrepancies and payload irregularities to classify traffic without reliance on machine learning. Through controlled experiments using synthetic fragmented traffic, we show how fragmentation behaviors map directly to geopolitical and cybersecurity-driven disruptions. This session will bridge the gap between global governance debates and low-level protocol behaviors, offering tools and insights for analysts, researchers and defenders navigating an increasingly segmented digital landscape. We asked Vladimer a few more

Read More