Network evasion and misinformation detection are disclosed. Techniques are
provided for network security, including determining whether a particular
packet, segment, frame, or other data encapsulation has been
retransmitted. By detecting and tracking retransmits, the packet may be
compared to the original packet to determine whether an attack exists. By
evaluating the original data stream and a copy of the original data
stream modified with the retransmitted packet, an evasion or
misinformation attempt may be detected, invoking pattern or signature
matching to determine whether an attack is attempted against a target
host.