New issue 18: Threat discussion

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
At the San Diego meeting I promised to create a new issue
about the various threats the protocol should consider.

So far, we have at least the following (notation: the IKE
peers are A and B; C is an innocent victim).

  1) Unauthenticated attacker directs the traffic stream
     from B to a third party C, with the intent flooding C
     with unwanted traffic.

  2) Authenticated peer A directs the traffic stream from B
     to a third party C, with the intent of flooding C with
     unwanted traffic.

  3) Unauthenticated attacker directs the traffic stream
     from B to somewhere (perhaps to the attacker or /dev/null), 
     with the intent of preventing the legitimate peers from 
     communicating.

  4) Unauthenticated attacker causes the IKE_SA to be
     closed by modifying just one or two IKE packets (if
     attacker can modify all packets, he can of course DoS).

Do we have any other threats, assuming we don't need to 
repeat those where MOBIKE doesn't change anything in
normal IKEv2? Should we add some discussion about these 
to the design document and/or protocol proposals?

(BTW, a comment about terminology: Francis has quite
consistently called case 1 "transient pseudo-NAT attack" 
and case 2 "third party bombing". I (and several others) 
have sometimes called both 1 and 2 third party bombing.)

Cheers,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.