Introducing the nDPI TCP Fingerprint: A Stable, Patent-Free Way to Fingerprint TCP Stacks
Every TCP connection starts with a SYN, and that first packet says a lot about the machine that sent it. The Linux, Windows, macOS and Android stacks each set different flags, choose different initial TTLs, advertise different receive windows, and, above all, lay out their TCP options in different orders. Passive TCP fingerprinting turns those differences into a compact signature. Today we are announcing the nDPI TCP Fingerprint (NTF), a modern, open, patent-free TCP fingerprint format that has been included in nDPI for a few years now. It is implemented …
