Artículos del equipoOperar una red

IP Spoofing: What It Is and How to Protect Yourself

What a forged source address can and cannot do, why replies matter, and how source validation differs from proving a user's identity.

Índice

Two white envelopes carry matching blue house symbols, with one sender label peeling away.
A return address can be copied. It tells the recipient where to reply, but does not prove who sent the message.

A letter can carry your return address even when you did not send it. The address tells the recipient where a reply should go; it does not prove who wrote the letter. IP spoofing exploits a similar gap in Internet communication.

What is being forged?

Information travels across a network in packets. Each IP packet has a destination address and a source address. Spoofing means putting a false source address in that packet. The receiver sees the claimed source, unless another mechanism checks whether it makes sense.

An IP address helps networks deliver traffic. It is not a person's identity card. Several people may share one public address, and a device's address can change. A rule that allows traffic from a particular IP therefore answers a narrower question than a login or a cryptographic identity check.

Why the reply matters

Suppose someone sends a request with your address as its source. The service normally sends its reply towards you. The sender does not automatically receive that reply or gain access to your computer.

This matters for TCP, the transport used by many applications: opening a connection requires an exchange in both directions, and established connections track their own state. Merely copying an address does not complete that exchange. The TCP specification describes those connection and sequence checks. They are useful protections, but they are not a replacement for authenticating the service or user.

How a forged address can still cause harm

An attacker may not want a conversation. They may want a service to send unwanted replies to somebody else. If many services respond, the victim receives traffic they never requested. This is a reflection attack. If the replies are much larger than the requests, it also creates amplification.

Other attacks try to exhaust resources directly or exploit a service that places too much trust in a source address. The result depends on the service, the network path and its protections. Spoofing alone does not give someone the ability to read an encrypted session or take over an account.

Two different checks, in two different places

At a network boundary, an operator can reject traffic claiming a source that should not arrive on that connection. For example, a customer's connection should not send packets pretending to belong to an unrelated customer's address range. This is the principle behind BCP 38 source filtering.

At the application, authentication checks who is entitled to participate. HTTPS uses TLS to authenticate the server and protect the connection when configured and validated correctly; signing in establishes a separate account identity. A valid-looking address cannot replace either check.

What you can do

If you use the Internet rather than operate a network, keep software updated, use services with authenticated encrypted connections, and take certificate warnings seriously. These protect the conversations you participate in. Filtering forged traffic across an Internet connection is work for the network operator; it is not something a stronger password can do.

If you run a network or service, start with where to place source checks and authentication. For a clearer picture of reflection, flooding and related terminology, continue to the different attack patterns.

Look for the mechanism behind the claim

The useful habit here is to ask what a system actually verifies. Lu Heng takes that question into a broader discussion of institutions and power in Note 20, on reality layers and symbolic power. That essay develops a wider argument; the networking example here is simply a concrete way to distinguish a claim from the mechanism that supports it.