Re: Problems with implementation - DoS attacks possible
Tomasz Grabowski <[email protected]> Tue, 21 Jan 2003 20:14:34 +0100 (CET)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 21 Jan 2003, Naohiro Fukuda wrote: [...] > (2) The collector handles that if the ICMP traceback message in the buffer-1 > is not valid as a result of the authentication, flushing the message > or move it to another buffer-2, second. > > (3) Finally, the buffer-1 keeps only valid ICMP traceback message. But the problem remains. The collector can't authenticate the message right after the message is retrived. It must *wait* for the proper key to be disclosured by the remote router/host/whatever. It will take minutes, hours or maybe days(?). So I think your proposition isn't quite suitable for this. > > I think the problem is how to keep the speed of authentication. Yes, but collector *can't* speed up the authentication process. Look above. > i) Increase the size of buffer-1 Assuming I have 622 Mbps speed and I'm flooded with ICMP Traceback messages. The time beetwen key change is one hour. Imagine how big buffer-1 must be... > ii) Accelarate the process of authentication But in proposed authentication scheme the process can't be accelerated by collector. > iii) Configure the lifetime of the key much longer I rather hoped it will be much shorter :) --- Tomasz Grabowski (0-91)4494234 Akademickie Centrum Informatyki mailto:[email protected]