Re: Problems with implementation - DoS attacks possible
Mikael Olsson <[email protected]> Fri, 24 Jan 2003 09:25:24 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
Marcus Leech wrote: > > Tomasz Grabowski wrote: > > 2. After key change we should send ICMP Traceback messages to hosts to > > which we sended previous ICMP Traceback messages (hashed with previous > > key). > > I like solution number 2. It doesn't increase traffic volume appreciably, and > I can't see that it does any harm. In a DDoS situation, of course, it may > get dropped. This is better than nothing. I think this idea needs to be nipped in the bud. Consider the number of hosts one would have to track. Backbone routers would have to track heaploads of hosts even during normal traffic. Maybe they can cope with it, maybe not. However, small edge routers would have to track heaploads of hosts during random source DDoS. Remember that we also send tracebacks to the source IPs, so these routers would suddenly have to remember all these fake addresses and send key disclosures to all of them. -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com