Summary

  • RFC 3514 was an Informational, Independent Stream April 1 satire, not an Internet Standard or evidence of a deployed security control.
  • Its evil bit makes the attacker supply the verdict consumed by the firewall. A false zero defeats protection; a false one can manufacture denial of service.

The tempting way to remember RFC 3514 is as a one-line Internet joke: attackers were instructed to mark their own packets as evil. That summary is accurate but incomplete. The document built a miniature security system around the joke. It specified who should set the bit, how fragments should carry it, how relays and translators should revise it, how firewalls should enforce it, how intrusion-detection systems should correct mistakes, and what happens when the label is wrong. Read as institutional history, the comedy is a stress test of delegated judgment.

The publication identity matters first. “The Security Flag in the IPv4 Header,” by Steven M. Bellovin, is dated 1 April 2003. Its status is Informational, and its own status statement says it does not specify an Internet standard of any kind. The Datatracker records the document in the Independent Stream. The RFC Editor's subject registry places RFCs like this under humor: the April 1 series and other whimsical documents. RFC 2555, a history written for the series' thirtieth anniversary, also acknowledges poetry and humor, especially on April 1.

Those facts are not decorative disclaimers. Without them, a later reader could mistake RFC 2119 words such as MUST and SHOULD for evidence of a serious deployment plan. The capitalized vocabulary is part of the parody. It borrows the administrative voice of protocol specification, then applies that voice to a premise that collapses as soon as one asks who controls the input.

RFC 3514 assigns the high-order bit of the IPv4 Fragment Offset field to a security flag, commonly called the evil bit. Zero means the packet has no evil intent. Hosts and network elements are told to assume such a packet is harmless and not take defensive measures. One means the packet has evil intent, and secure systems are advised to defend themselves.

The decisive clause follows: attack programs MUST set the bit. The actor whose behavior is under suspicion gets to write the classification that the defensive system will consume. The bit is syntactically objective—it is either zero or one—but its supposed meaning is a statement supplied by the interested party. The field can be observed; the intent cannot be inferred from that observation without another trust mechanism.

The document heightens the contradiction by treating compliance as if it extended through every awkward case. Hand-crafted attack packets must mark themselves. Systems used to launder attacks should preserve the declaration. Trusted internal hosts must not set the bit because the satire declares it axiomatic that attackers are outside the firewall. A port scanner should distinguish hostile reconnaissance from benign research. Each rule forces a real attribution problem into a binary moral confession.

Fragmentation turns the bit into a lesson about observation points. Dangerous fragments must carry it. When an intermediary fragments a packet whose pieces are not individually dangerous, the intermediary is told to clear the bit and restore it after reassembly. The same higher-level act can therefore appear with different labels along one path. An observer needs to know where the capture occurred, which system transformed the packet, and what unit of behavior was being judged.

NAT and proxies deepen that problem. Because a traditional NAT modifies packets, RFC 3514 assigns it responsibilities for marking malicious transformations. A transparent proxy that discovers evil content is also expected to set the bit. Now the value no longer even pretends to be solely the sender's declaration. It can be rewritten by middleboxes whose identity, policy and inspection scope are outside the single bit.

The enforcement rule is deliberately absolute. Firewalls MUST drop packets with the bit set and MUST NOT drop packets with it clear. A security decision is thus reduced to an unauthenticated input controlled by an endpoint or intermediary. If the defender applies the rule faithfully, an attacker clears the bit and passes. If the defender distrusts the bit and inspects other evidence, the bit is no longer doing the work claimed for it.

Intrusion-detection systems get a revealing escape hatch. RFC 3514 allows them to apply probabilistic correction for false positives and false negatives. That concession quietly reintroduces the hard problem the bit was supposed to eliminate: independent classification based on behavior, context and imperfect observations. Once an IDS must decide that the declared value is wrong, the packet's self-description becomes just another feature, not a verdict.

Routers not acting as security devices are told to ignore the field. This separates carriage from judgment. A forwarding system can move a packet without claiming to know the sender's purpose. A firewall can act only under a policy owned by someone. A sensor can record a value without authenticating who selected it. These are different functions, even when they run on the same appliance.

Section 7 states the failure modes with unusual clarity. Correct functioning depends critically on the evil bit being set properly. If a faulty or dishonest component leaves a malicious packet at zero, the firewall cannot do its assigned job. If a benign packet is marked one, denial of service may result. False negatives transfer control to the attacker; false positives turn the control itself into a weapon.

The errata record should also be read in genre. RFC 3514 has editorial reports, including one whose verifier note jokes that the reporter should have posted it on April 1. Errata document corrections or disagreements around the published text. They do not make the memo a standard, demonstrate implementation, or supply operational ground truth.

In September 2026, draft-traviss-evil-byte-00 extended the joke. It says that senders cannot be relied upon to set the evil bit and proposes an eight-bit rating written by a “Morality-Inspecting Trusted Middleman.” The document is an Internet-Draft, explicitly work in progress, with an expiry date. Its claims about operational experience belong to its satire, not to a measurement study. It is valuable here only as evidence that the original joke remains a language for criticizing self-reporting, centralized scoring and inspection authority.

The architectural lesson is narrower and more durable than either parody. A field is evidence that a field held a value at a named observation point. It is not automatically evidence of the intent it names. To move from bit to security judgment, an operator needs provenance, integrity, behavioral observations, a policy, an enforcement receipt and an outcome. Each is controlled by different actors and can fail independently.

Heng Lu's reality-layer distinction helps explain the gap. The label lives in symbolic reality: it is a compact, interoperable claim. The attack, the authorization decision and the harm live in operational and physical reality. A symbol can coordinate honest participants, but it cannot coerce honesty from an adversary merely because a specification prints MUST beside it.

This does not mean labels are useless. Authenticated labels issued by accountable parties can reduce ambiguity. Classifier outputs can guide triage when their model, confidence and observation window are preserved. Policy tags can make enforcement reproducible when their issuer and version are known. The error is to erase those conditions and present the label as self-authenticating truth.

RFC 3514 survives because its joke reaches the control surface quickly. It asks the packet to tell the firewall whether the firewall should distrust it. Everything that follows—fragment rules, middlebox rewriting, probabilistic correction and denial of service—shows why the answer cannot close the case. The packet may declare itself harmless. The declaration is still only the packet's claim.

Sources