Re: Attacking TTL-based "authentication"

Mikael Olsson <[email protected]> Sat, 18 Oct 2003 21:52:08 +0200
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
Tomasz Grabowski wrote:
>=20
> [look ma, if i'm connected to router R, I can implicate
>  someone else behind that router!]

Use of unauthenticated itrace requires that one acknowledge that this
can happen.  So, while we can't know for _sure_ that the attacker is
behind any given router, we can tell that they're somewhere on the=20
path of routers that we've mapped out. =20

In the majority of cases, this will narrow down the problem from=20
"the Internet hates us. let's go have a beer." to "I know which ISP=20
to call" -- and this is a major improvement. =20

Remember the threat scenario we're trying to defend against: DDoS=20
slaves scattered all over the 'net.


--=20
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com