Re: Problems with implementation - DoS attacks possible

Naohiro Fukuda <[email protected]> Wed, 22 Jan 2003 23:08:09 +0900
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
At 11:50 03/01/22 +0100, you wrote:

>On Wed, 22 Jan 2003, Naohiro Fukuda wrote:
>
> > I understood, thank you. i.e., the reason for the performance this 
> draft-03.txt
> >   does not allow to use "ICMP + HASH + SIG" combination, correct?
> >
> > But, thinking about the collector's performance, don't you think to admit it?
> >
> > If it required, I think, there is another solusion to implement RSA 
> accelerators
> > in ther routers for signing.
>
>This the quote from the draft:
>       The ideal form of authentication would be a digital signature.  It
>       is unlikely, though, that routers will be able to afford such
>       signatures on all Traceback packets.  Thus, although we leave hooks
>       for such a variant, we do not further define it at this time.
>
>So, the door are open.

Thank you.


> > > > If we use a PC of 1GB Memory as collector, the memory will be filled up
> > > >   about 10 seconds, though we need to backup the data to HDD until then.
> > >
> > >You need a big HDD to collect all messages :)
> > >What I'm saying here it is *not possible* to collect all messages (and
> > >yes, I'm connected 622 Mbps to the Internet and I recently experienced an
> > >attack at >500 Mbps speed).
> >
> > Oh... How much do you think the cost to achive the complete traceback
> > collector?
>
>First, you must collect all those messages. After the key change, you
>need to check hash on each of the messages. Meanwhile you need to still
>collect messages. Is it possible to make it in realtime?

Biggest problem is to collect all those messages. But, if we implement 
the router,
preparing several key paris and signing/storing them to reduce the time 
for signing,
then the performance problem of the router will get better, then creating 
traceback
message as to include hash, key, and signature, the message will be handled at
collector without waiting for the another key discorsure message.

Anyway, I think I need to implement it.

>I hoped itrace would be simple. It looks that collector can't be placed in
>router itself. It must be dedicated machine - a powerfull one.
>
>---
>Tomasz Grabowski  (0-91)4494234
>Akademickie Centrum Informatyki
>mailto:[email protected]

----------------------------------------------------------------------------------------
Naohiro Fukuda
Matsushita Electric Works, Ltd.
Network Security Team
New Business Promotion Division
Address: 5-13-2, Mita, Minato-ku, Tokyo 108-8351, Japan
Tel: +81-3-3452-3390 Fax: +81-3-5442-9156
(MIC)  :7-331-4856 (MIC-FAX)  :7-331-4869
E-mail: [email protected]
English Homepage: http://www.netcocoon.com
Japanese Homepage: http://www.nais-netcocoon.com
----------------------------------------------------------------------------------------