An IP fragmentation flood sends large volumes of fragmented packets, some of which are never completed, forcing receiving systems to hold reassembly buffers open and burn memory and CPU on fragments that will never form a usable packet.
Written for business and infrastructure decision-makers, not protocol engineers.
Large packets are sometimes split into fragments during transmission and reassembled by the receiving system. During a fragmentation flood, attackers send excessive numbers of fragments — often incomplete or overlapping — that consume reassembly buffer memory and processing time without ever producing legitimate traffic.
Staff have to hold shelf space for each partial shipment in case the rest arrives, but many never do. Enough incomplete shipments and the warehouse runs out of space for real inventory. A fragmentation flood applies the same pressure to a system's reassembly buffers.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
Availability risk that belongs in business-continuity planning.
Fragmentation-based attacks matter because reassembly is a stateful, resource-bound operation baked into how IP itself works — it can't be turned off without breaking legitimate traffic that genuinely needs fragmentation, which is why bounding and filtering fragment traffic is the practical defense.
Attacks against one customer can become an infrastructure and service-quality issue.
Availability, latency and shared network resources are immediately visible to end users.
If users cannot connect, they cannot transact, work or consume the service they pay for.
NeuroWall filters and rate-bounds fragmented traffic at the XDP layer before it can exhaust reassembly resources, alongside its broader UDP cost-based filtering for amplification-prone traffic patterns.
Book a Demo →An IP fragmentation flood sends large volumes of fragmented packets, many incomplete or overlapping, aiming to exhaust reassembly buffer memory and processing resources on the receiving system.
IP fragmentation allows large packets to traverse network segments with smaller maximum transmission units. It's a normal, legitimate part of how IP networking works.
Individual fragments may not contain enough information for a naive filter to evaluate, which is part of why fragmentation-based attacks and evasion techniques have historically been effective.
It can be. When distributed sources generate the traffic simultaneously, it is a distributed denial-of-service attack.
Yes. NeuroWall filters and rate-bounds fragmented traffic as part of its DDoS protection capabilities.