| Newsgroups |
gmane.ietf.mobike |
| Message-ID |
<[email protected]> |
At the San Diego meeting I promised to create a new issue
about the various threats the protocol should consider.
So far, we have at least the following (notation: the IKE
peers are A and B; C is an innocent victim).
1) Unauthenticated attacker directs the traffic stream
from B to a third party C, with the intent flooding C
with unwanted traffic.
2) Authenticated peer A directs the traffic stream from B
to a third party C, with the intent of flooding C with
unwanted traffic.
3) Unauthenticated attacker directs the traffic stream
from B to somewhere (perhaps to the attacker or /dev/null),
with the intent of preventing the legitimate peers from
communicating.
4) Unauthenticated attacker causes the IKE_SA to be
closed by modifying just one or two IKE packets (if
attacker can modify all packets, he can of course DoS).
Do we have any other threats, assuming we don't need to
repeat those where MOBIKE doesn't change anything in
normal IKEv2? Should we add some discussion about these
to the design document and/or protocol proposals?
(BTW, a comment about terminology: Francis has quite
consistently called case 1 "transient pseudo-NAT attack"
and case 2 "third party bombing". I (and several others)
have sometimes called both 1 and 2 third party bombing.)
Cheers,
Pasi