Re: Problems with implementation - DoS attacks possible
Tomasz Grabowski <[email protected]> Thu, 23 Jan 2003 17:35:43 +0100 (CET)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
> > "Taylor, Tom-PT [CAR:5N00:EXCH]" wrote: > > > > Does option 2 mean that the router has to hang on to a list of hosts to which it sent > > messages using the latest key, then send them messages containing only a key disclosure > > element when the key changes? > > > Yes, I think that's what it means. If the key changes relatively frequently, the > list will be relatively short. It has much to do with keys lifetime AND probability of Traceback generation. How many packets are processing backbone routers on Gigabit networks? How many ICMP Traceback messages they will produce in keylife period of time? Is it possible to hang on a complete list of hosts to which it sent Traceback messages? Incrase in traffic, caused by additional messages, will not be significant (I've got some ideas on how to decrease it very much). The _real_ problem is the host table on router. --- Tomasz Grabowski (0-91)4494234 Akademickie Centrum Informatyki mailto:[email protected]