Re: Problems with implementation - DoS attacks possible
Mikael Olsson <[email protected]> Tue, 21 Jan 2003 19:26:08 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Naohiro Fukuda wrote: > > If attacker will send ICMP tarceback messages with various fake authentications, > CRLs request will also be issued for the validation. If many classed CAs exsist, > it will be delayed much more. > > I think if it is not realtime traceback, it can be meaningful for forensics. I've got to admit that this isn't making sense to me. Either you're two steps ahead in your line of thinking, or you haven't understood the dynamics of the key disclosure algorithm: when I receive a packet, I have to _wait_ to find out what the key was used in its HMAC. It's not just an issue of "it takes time to connect to the web server and retreive the certificate". I have to wait until the router that originated the traceback message decides to change its key and send a new traceback my way, a process which I cannot force. Hey, there's an interesting thought. Moving DDoS. If key disclosure takes a "long" time, e.g. one hour, one could switch zombies once in a while to hope that their locations are never fully disclosed/authenticated. Sure, we'll get plenty of tracebacks, but we won't be able to authenticate them until we get another traceback from a router close to the DDoS zombie. And if the zombie decides to shut up, that might be "never". Or at least days later, during which time said zombie has had time to wreak havoc in other places. Again: what kind of time periods are we talking about for key disclosure? A few minutes? Hours? (Of course, in an ideal future world, where itrace has been implemented in "all" routers, authentication becomes less important; one can construct complete route chains with high degrees of trust without it.) -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com