Re: Problems with implementation - DoS attacks possible
Mikael Olsson <[email protected]> Wed, 22 Jan 2003 18:59:30 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Naohiro Fukuda wrote: > > Biggest problem is to collect all those messages. But, if we > implement the router preparing several key paris and > signing/storing them to reduce the time for signing, then the > performance problem of the router will get better, then creating > traceback message as to include hash, key, and signature, the > message will be handled at collector without waiting for the > another key discorsure message. Um. I still don't think you've understood the problem. Big backbone routers that forward several gigabit of data each second CANNOT afford to pubkey sign each packet itrace packet. Your suggestion of "preparing" keys doesn't help. Even if we prepare 1 million keys, on such backbone routers, this fails after only a few seconds when the key list has been exhausted; we're back to generating keys on-the-fly, which, again, they don't have the CPU for. The situation is just as bad on small edge routers. They don't come equipped with pentium class CPUs. They come with small CPUs that are dimensioned for management logic only. They do packet processing in custom ASICs. So, even if the data stream is much smaller, they still don't have the oomph to sign everything. And, even if through some Great Miracle, all routers suddenly started emitting pubkey signed itraces, what kind of hardware do we want to require at the collectors? We want people with "normal" internet connections to be able to do this on the equivalent of a standard PC. We do NOT want to require boxes equipped with crypto accelerators. -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com "Senex semper diu dormit"