Re: Problems with implementation - DoS attacks possible

Naohiro Fukuda <[email protected]> Sat, 25 Jan 2003 19:28:42 +0900
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
Hello,

I have a question about the KEY CHANGE INTERVAL;

I'm sorry I do not have any background around  key change interval of key 
disclosure,

Why do most of yours imagine the time interval around minutes, second, or hours?

#I think the basic technology of PKI is very strong, so I think weeks or 
months level  is acceptable.

Could you please tell me the reason why ?

Best Regards,


At 11:14 03/01/24 -0500, Marcus Leech wrote:
>Mikael Olsson wrote:
> >
> >
> > Backbone routers would have to track heaploads of hosts even
> > during normal traffic.  Maybe they can cope with it, maybe not.
> >
> > However, small edge routers would have to track heaploads of
> > hosts during random source DDoS. Remember that we also send
> > tracebacks to the source IPs, so these routers would suddenly have
> > to remember all these fake addresses and send key disclosures to
> > all of them.
> >
>A backbone router at 2.8gbits/sec handles (on average) about 1.75 
>packets/second.
>   With a probability for ITRACE emission of 1/20,000, that's 87 ITRACE 
> packets/second.
>   If the key change interval is 1 minute, and those 87 packets/second 
> were all to
>   different hosts (which they likely won't be under DDoS conditions), 
> we have to
>   remember about 5250 IP addresses, or about 160kbytes of memory for IPV6.
>
>
>--
>----------------------------------------------------------------------
>Marcus Leech                             Mail:   Dept 8M70, MS 012, FITZ
>Advisor                                  Phone: (ESN) 393-9145  +1 613 763 9145
>Security Architecture and Planning       Fax:   (ESN) 393-9435  +1 613 763 9435
>Nortel Networks                          [email protected]
>-----------------Expressed opinions are my own, not my employer's------