Re: Problems with implementation - DoS attacks possible

Mikael Olsson <[email protected]> Fri, 24 Jan 2003 09:25:24 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
Marcus Leech wrote:
> 
> Tomasz Grabowski wrote:
> > 2. After key change we should send ICMP Traceback messages to hosts to
> > which we sended previous ICMP Traceback messages (hashed with previous
> > key).
>
> I like solution number 2.  It doesn't increase traffic volume appreciably, and
>   I can't see that it does any harm.  In a DDoS situation, of course, it may
>   get dropped.  This is better than nothing.

I think this idea needs to be nipped in the bud.
Consider the number of hosts one would have to track.

Backbone routers would have to track heaploads of hosts even
during normal traffic.  Maybe they can cope with it, maybe not.

However, small edge routers would have to track heaploads of
hosts during random source DDoS. Remember that we also send
tracebacks to the source IPs, so these routers would suddenly have 
to remember all these fake addresses and send key disclosures to 
all of them.


-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com