Compliance Node Overview
MITRE CAPEC-331 (ICMP IP Total Length Field Probe) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary sends a UDP packet to a closed port on the target machine to solicit an IP Header's total length field value within the echoed 'Port Unreachable" error message. This type of behavior is useful for building a signature-base of operating system responses, particularly when error messages contain other types of information that is useful identifying specific operating system responses. Likelihood of attack: Medium. Typical severity: Low. Maps to weaknesses CWE-204.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/331.html
SHA-256 integrity: 1f18e5de23bad2f61a519661f0890597a7204b2123547b1058f026a5761e7ddf
Primary Citations — 7 traced to source
- MITRE CAPEC-331: ICMP IP Total Length Field Probe (https://capec.mitre.org/data/definitions/331.html)
- CWE-204: underlying weakness (http://cwe.mitre.org/data/definitions/204.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.