All the artificial tools make tiny fragments and thus can be spotted as
suspicious. In other words using the nmap -f flag stands for "find me
in the IDS logs."  :-)

Afaik, fragmentation was originally meant to handle mediation between
devices with different MTU while the higher layer algorithms (e.g. TCP) 
hunts around for optimized values.  I've never really seen any net 
devices with MTUs smaller than 512 bytes/characters... (ATM 53 byte 
cells included because they have their own SAR function and buffers
at the AAL5 sublayer.)

So all those small fragments should either be the remnants on
the tail end of a packet or are indicative of some "synthetic"
traffic (i.e. hacking) tool. I would love to hear about any 
contradictory real life traffic that negates this observation....


