This paper presents a one-year study of Internet packet traffic from a large campus network, showing that 15-25% of TCP connections have at least one TCP RST (reset). Similar results have also been observed from measurements of other Internet links. The results in this paper show that reset connections arise from local events such as network outages, attacks, or reconfigurations, as well as from global trends in TCP usage. In particular, we identify application-level Web behaviour as the primary contributor to the global trend in reset TCP connections. The most prevalent anomaly is the absence of the normal FIN handshake for connection termination. Instead, connections are often reset by the client. We believe that particular implementations of HTTP/TCP connection management cause this global trend.
Martin F. Arlitt, Carey L. Williamson