Compliance Node Overview
MITRE CAPEC-319 (IP (DF) 'Don't Fragment Bit' Echoing Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This OS fingerprinting probe tests to determine if the remote host echoes back the IP 'DF' (Don't Fragment) bit in a response packet. An attacker sends a UDP datagram with the DF bit set to a closed port on the remote host to observe whether the 'DF' bit is set in the response packet. Some operating systems will echo the bit in the ICMP error message while others will zero out the bit in the response packet. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-200.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/319.html
SHA-256 integrity: 4a4449de33c25fef1a87252afe45f49a0fb0e9cee2e71e6c0b24e256053d9bb8
Primary Citations — 7 traced to source
- MITRE CAPEC-319: IP (DF) 'Don't Fragment Bit' Echoing Probe (https://capec.mitre.org/data/definitions/319.html)
- CWE-200: underlying weakness (http://cwe.mitre.org/data/definitions/200.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.