Re: New issue 18: Threat discussion
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote:
So far, we have at least the following (notation: the IKE
peers are A and B; C is an innocent victim).
=> I disagree a bit about the presentation: the level of authentication
is very important too. With other words, we shall have to give to
the return routability procedure(s) a trust level.
1) Unauthenticated attacker directs the traffic stream
from B to a third party C, with the intent flooding C
with unwanted traffic.
2) Authenticated peer A directs the traffic stream from B
to a third party C, with the intent of flooding C with
unwanted traffic.
3) Unauthenticated attacker directs the traffic stream
from B to somewhere (perhaps to the attacker or /dev/null),
with the intent of preventing the legitimate peers from
communicating.
=> 1 and 3 should be merged?
4) Unauthenticated attacker causes the IKE_SA to be
closed by modifying just one or two IKE packets (if
attacker can modify all packets, he can of course DoS).
Do we have any other threats, assuming we don't need to
repeat those where MOBIKE doesn't change anything in
normal IKEv2? Should we add some discussion about these
to the design document and/or protocol proposals?
(BTW, a comment about terminology: Francis has quite
consistently called case 1 "transient pseudo-NAT attack"
and case 2 "third party bombing". I (and several others)
have sometimes called both 1 and 2 third party bombing.)
=> if you have read my draft about case 1 you know why I has
considered cases 1/3 as very different of case 2. BTW the
attack and the defense are very bound to NAT traversal capability,
when the case 2 is essentialy a question of trust in the peer
(this is why the level of trust is so critical), and the name
comes from MIPv6 security discussion (Erik or Jari?).
Thanks
[email protected]
PS: draft-dupont-transient-pseudonat-04.txt
(any comment and/or improvement are wellcome)