Re: Attacking TTL-based "authentication"
Mikael Olsson <[email protected]> Sat, 18 Oct 2003 21:52:08 +0200
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Tomasz Grabowski wrote: >=20 > [look ma, if i'm connected to router R, I can implicate > someone else behind that router!] Use of unauthenticated itrace requires that one acknowledge that this can happen. So, while we can't know for _sure_ that the attacker is behind any given router, we can tell that they're somewhere on the=20 path of routers that we've mapped out. =20 In the majority of cases, this will narrow down the problem from=20 "the Internet hates us. let's go have a beer." to "I know which ISP=20 to call" -- and this is a major improvement. =20 Remember the threat scenario we're trying to defend against: DDoS=20 slaves scattered all over the 'net. --=20 Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com