Re: Problems with implementation - DoS attacks possible
Naohiro Fukuda <[email protected]> Sat, 25 Jan 2003 19:28:42 +0900
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
Hello, I have a question about the KEY CHANGE INTERVAL; I'm sorry I do not have any background around key change interval of key disclosure, Why do most of yours imagine the time interval around minutes, second, or hours? #I think the basic technology of PKI is very strong, so I think weeks or months level is acceptable. Could you please tell me the reason why ? Best Regards, At 11:14 03/01/24 -0500, Marcus Leech wrote: >Mikael Olsson wrote: > > > > > > Backbone routers would have to track heaploads of hosts even > > during normal traffic. Maybe they can cope with it, maybe not. > > > > However, small edge routers would have to track heaploads of > > hosts during random source DDoS. Remember that we also send > > tracebacks to the source IPs, so these routers would suddenly have > > to remember all these fake addresses and send key disclosures to > > all of them. > > >A backbone router at 2.8gbits/sec handles (on average) about 1.75 >packets/second. > With a probability for ITRACE emission of 1/20,000, that's 87 ITRACE > packets/second. > If the key change interval is 1 minute, and those 87 packets/second > were all to > different hosts (which they likely won't be under DDoS conditions), > we have to > remember about 5250 IP addresses, or about 160kbytes of memory for IPV6. > > >-- >---------------------------------------------------------------------- >Marcus Leech Mail: Dept 8M70, MS 012, FITZ >Advisor Phone: (ESN) 393-9145 +1 613 763 9145 >Security Architecture and Planning Fax: (ESN) 393-9435 +1 613 763 9435 >Nortel Networks [email protected] >-----------------Expressed opinions are my own, not my employer's------