Abstract
Despite its crucial role in network diagnostics, error reporting, and Path MTU Discovery (PMTUD), the unauthenticated nature of the Internet Control Message Protocol (ICMP) makes it a potential target for volumetric attacks, covert channels, and network reconnaissance. Consequently, network administrators face a critical challenge: blocking all ICMP traffic effectively reduces the attack surface but disrupts essential functions such as PMTUD and traceroute, whereas permitting unrestricted ICMP traffic increases the risk of infrastructure abuse. This paper presents a systematic quantitative study of the trade-off between ICMP's diagnostic utility, associated security risks, and operational efficiency. We propose a balanced ICMP policy framework that classifies ICMP message types, selectively permits essential error messages, applies rate limiting to diagnostic probes (5–10 packets per second per source), and blocks obsolete or high-risk message types. The proposed framework is evaluated through a series of experiments conducted in a controlled testbed under ICMP flood and reflection attack scenarios. Three policy archetypes—Balanced, Block-all, and Permissive are comparatively analyzed using diagnostic, security, and performance metrics. Experimental results demonstrate that the Balanced policy achieves a 94% PMTUD success rate and a 91% traceroute completion rate while reducing the attack surface by 73%. Furthermore, under ICMP flood attacks, the proposed policy limits TCP throughput degradation to only 12%, providing an effective balance between network functionality, security, and operational performance
References
1. Singh AK, Chen M, Zhang L. Adaptive rate limiting for ICMP flood mitigation in softwaredefined networks. IEEE Trans Netw Serv Manag. 2022 Sep;19(3):2456–70.
2. Lee JJ, Patel S, Gupta R. Silent failures: The impact of ICMP blocking on Path MTU Discovery
in IPv6. In: Proc IEEE INFOCOM; 2023 May; London, UK. p. 1–10.
3. Rahman MT, Kim H, Li Y. ICMPv6 reflection amplification: A large-scale measurement study.
IEEE/ACM Trans Netw. 2023 Apr;31(2):567–81.
4. Santos ED, De Rose CAF. Traceroute in the dark: Diagnosing network paths without ICMP. In:
Proc ACM SIGCOMM; 2024 Aug; Amsterdam, The Netherlands. p. 342–55.
5. Johnson NB, Abadi RO, Watson TJ. Covert channels over ICMP: Detection using ensemble
learning. IEEE Trans Inf Forensics Security. 2023 Jan;18:1123–37.
6. Verma PK, Das SK, Sen A. A game-theoretic approach to ICMP rate limiting in multi-tenant
cloud networks. In: Proc IEEE Int Conf Cloud Comput (CLOUD); 2025 Jul; Chicago, IL. p.
89–98.
7. Wang HY, Zhou LX, Liu F. Are we over-filtering ICMP? An empirical study of 10 000
enterprise networks. IEEE J Sel Areas Commun. 2024 Feb;42(2):310–25.
8. Adewale OS, Fall KR. QUIC and the diminishing role of ICMP: A performance analysis. In: Proc
ACM Internet Measurement Conf (IMC); 2024 Oct; Los Angeles, CA. p. 178–92.
9. Schmidt MC, Clausen TH, Andersson JI. Neighbor Discovery flooding attacks in IPv6:
Mitigation using ICMPv6 rate limiting. IEEE Commun Lett. 2024 May;28(5):1024–8.
10. Saha RK, Greenberg AG, McKeown N. Revisiting ICMP in data center networks: A case for
selective error propagation. In: Proc IEEE Symp High-Performance Interconnects (HOTI);
2025 Aug; Santa Clara, CA. p. 45–52.

This work is licensed under a Creative Commons Attribution 4.0 International License.
