Re: Problems with implementation - DoS attacks possible

Mikael Olsson <[email protected]> Wed, 22 Jan 2003 18:59:30 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
Naohiro Fukuda wrote:
> 
> Biggest problem is to collect all those messages. But, if we 
> implement the router preparing several key paris and 
> signing/storing them to reduce the time for signing, then the 
> performance problem of the router will get better, then creating
> traceback message as to include hash, key, and signature, the 
> message will be handled at collector without waiting for the 
> another key discorsure message.

Um. I still don't think you've understood the problem.

Big backbone routers that forward several gigabit of data each second
CANNOT afford to pubkey sign each packet itrace packet.

Your suggestion of "preparing" keys doesn't help.  Even if we prepare
1 million keys, on such backbone routers, this fails after only a 
few seconds when the key list has been exhausted; we're back to
generating keys on-the-fly, which, again, they don't have the CPU for.

The situation is just as bad on small edge routers. They don't come
equipped with pentium class CPUs. They come with small CPUs that are
dimensioned for management logic only. They do packet processing in 
custom ASICs. So, even if the data stream is much smaller, they still 
don't have the oomph to sign everything.


And, even if through some Great Miracle, all routers suddenly started
emitting pubkey signed itraces, what kind of hardware do we want to
require at the collectors?  We want people with "normal" internet 
connections to be able to do this on the equivalent of a standard PC.
We do NOT want to require boxes equipped with crypto accelerators.


-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com

"Senex semper diu dormit"