Re: New issue 18: Threat discussion
"Mohan Parthasarathy" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <01a101c49149$bda565f0$861167c0@adithya> |
Pasi,
Couple of questions
----------------------------------
At the San Diego meeting I promised to create a new issue
about the various threats the protocol should consider.
So far, we have at least the following (notation: the IKE
peers are A and B; C is an innocent victim).
1) Unauthenticated attacker directs the traffic stream
from B to a third party C, with the intent flooding C
with unwanted traffic.
mohanp> Is this attack where the unauthenticated attacker is modifying
mohanp> the packets of the authenticated client or doing the attack
mohanp> independently ?
2) Authenticated peer A directs the traffic stream from B
to a third party C, with the intent of flooding C with
unwanted traffic.
3) Unauthenticated attacker directs the traffic stream
from B to somewhere (perhaps to the attacker or /dev/null),
with the intent of preventing the legitimate peers from
communicating.
mohanp> Why is this different from (1) ?
4) Unauthenticated attacker causes the IKE_SA to be
closed by modifying just one or two IKE packets (if
attacker can modify all packets, he can of course DoS).
Do we have any other threats, assuming we don't need to
repeat those where MOBIKE doesn't change anything in
normal IKEv2? Should we add some discussion about these
to the design document and/or protocol proposals?
(BTW, a comment about terminology: Francis has quite
consistently called case 1 "transient pseudo-NAT attack"
and case 2 "third party bombing". I (and several others)
have sometimes called both 1 and 2 third party bombing.)
Cheers,
Pasi
-mohanp
_______________________________________________
Mobike mailing list
[email protected]
https://www.machshav.com/mailman/listinfo.cgi/mobike