Re: issue 45 - clarifications to security considerations

Mohan Parthasarathy <[email protected]> Mon, 7 Nov 2005 17:52:18 -0800 (PST)
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
sounds good to me.

-mohan

--- [email protected] wrote:

> Jari Arkko wrote:
> 
> > Here's another attempt:
> >
> >   Such an attack could also be defeated by use of
> negative
> >   acknowledgements, such as TCP RST and ICMP
> errors. However, in
> >   our case the victim lacks a valid SA and, as a
> result, is
> >   incapable providing any other negative
> acknowledgements than
> >   ICMP errors. Such errors may be filtered in many
> networks, and
> >   has some denial-of-service issues itself.
> 
> Hmm.. here's my take (add this to the end of the
> section):
> 
>    The duration of the attack can also be limited if
> the victim
>    reports the unwanted traffic to the originating
> IPsec tunnel
>    endpoint using ICMP error messages or INVALID_SPI
>    notifications. As described in [IKEv2] Section
> 2.21, this SHOULD
>    trigger a liveness test, which also doubles as a
> return
>    routability check if the COOKIE2 notification is
> included.
> 
> And while we're at it, we could also make the 3rd
> paragraph
> (the one referring to [Aura02] and transport layer
> acks) 
> more accurate:
> 
>    If the attack is launched by an outsider, the
> traffic flow would
>    normally stop soon due to the lack of responses
> (such as
>    transport layer acknowledgements). However, if
> the original
>    recipient of the flow is malicious, it could
> maintain the traffic
>    flow for an extended period of time, since it
> often would be able
>    to send the required acknowledgements (see
> [Aura02] for more
>    discussion).
> 
> Does this look ok?
> 
> Best regards,
> Pasi
> _______________________________________________
> Mobike mailing list
> [email protected]
> https://www.machshav.com/mailman/listinfo.cgi/mobike
>