Evasion Techniques
NetSecOPEN includes evasion technique testing because real-world attackers rarely deliver malware or exploits in their plainest, most detectable form. Instead, they obfuscate, fragment, encode, or otherwise disguise malicious traffic to slip past security devices undetected. A next-generation firewall that catches a known threat in clean conditions may still fail when that same threat is wrapped in evasion methods such as IP fragmentation, TCP segmentation, HTTP compression tricks, or protocol-level manipulation. By testing against a defined set of evasion techniques, NetSecOPEN ensures that certified products demonstrate resilient detection—proving they identify and block threats not just in ideal conditions, but under the adversarial, real-world circumstances they're meant to defend against.
The current version of the Evasion Techniques test set is version 1.0.