Re: Problems with implementation - DoS attacks possible

Mikael Olsson <[email protected]> Tue, 21 Jan 2003 19:26:08 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>

Naohiro Fukuda wrote:
> 
> If attacker will send ICMP tarceback messages with various fake authentications,
> CRLs request will also be issued for the validation. If many classed CAs exsist,
>   it will be delayed much more.
> 
> I think if it is not realtime traceback, it can be meaningful for forensics.

I've got to admit that this isn't making sense to me. Either you're
two steps ahead in your line of thinking, or you haven't understood
the dynamics of the key disclosure algorithm: when I receive a packet,
I have to _wait_ to find out what the key was used in its HMAC.

It's not just an issue of "it takes time to connect to the web
server and retreive the certificate".  I have to wait until the
router that originated the traceback message decides to change 
its key and send a new traceback my way, a process which I cannot 
force.


Hey, there's an interesting thought. Moving DDoS. If key 
disclosure takes a "long" time, e.g. one hour, one could
switch zombies once in a while to hope that their locations
are never fully disclosed/authenticated.  Sure, we'll get
plenty of tracebacks, but we won't be able to authenticate
them until we get another traceback from a router close to
the DDoS zombie. And if the zombie decides to shut up, that
might be "never". Or at least days later, during which time 
said zombie has had time to wreak havoc in other places.

Again: what kind of time periods are we talking about for
key disclosure?  A few minutes? Hours?


(Of course, in an ideal future world, where itrace has been 
 implemented in "all" routers, authentication becomes less 
 important; one can construct complete route chains with high 
 degrees of trust without it.)

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com