Re: Problems with implementation - DoS attacks possible
Tomasz Grabowski <[email protected]> Wed, 22 Jan 2003 11:50:59 +0100 (CET)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 22 Jan 2003, Naohiro Fukuda wrote:
> I understood, thank you. i.e., the reason for the performance this draft-03.txt
> does not allow to use "ICMP + HASH + SIG" combination, correct?
>
> But, thinking about the collector's performance, don't you think to admit it?
>
> If it required, I think, there is another solusion to implement RSA accelerators
> in ther routers for signing.
This the quote from the draft:
The ideal form of authentication would be a digital signature. It
is unlikely, though, that routers will be able to afford such
signatures on all Traceback packets. Thus, although we leave hooks
for such a variant, we do not further define it at this time.
So, the door are open.
> > > If we use a PC of 1GB Memory as collector, the memory will be filled up
> > > about 10 seconds, though we need to backup the data to HDD until then.
> >
> >You need a big HDD to collect all messages :)
> >What I'm saying here it is *not possible* to collect all messages (and
> >yes, I'm connected 622 Mbps to the Internet and I recently experienced an
> >attack at >500 Mbps speed).
>
> Oh... How much do you think the cost to achive the complete traceback
> collector?
First, you must collect all those messages. After the key change, you
need to check hash on each of the messages. Meanwhile you need to still
collect messages. Is it possible to make it in realtime?
I hoped itrace would be simple. It looks that collector can't be placed in
router itself. It must be dedicated machine - a powerfull one.
---
Tomasz Grabowski (0-91)4494234
Akademickie Centrum Informatyki
mailto:[email protected]