Re: RR checks to avoid DoS attacks
"Dondeti, Lakshminath" <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Consider the notion of the cost of the attack to the attacker vs. the cost to the victim. So the attacker needs to buy a prepaid SIM card to subscribe to a VoD service provided via IPsec protection, and then have the stream be re-directed at the victim. To me that seems like an implausible scenario. There are other simpler ways to launch a DoS attack. If the said DoS attacks are the only reason for RR checks in IKE based signaling of mobility, I think that part of the protocol should be optional. best regards, Lakshminath Bill Sommerfeld wrote: >>I contend that the attacker has no incentive to carry on the attack >>after authenticating itself to a server that is going to be >>encrypting all that traffic. >> >> > >If the authenticated identity is disposable -- if it comes from the >equivalent of a prepaid SIM card bought for cash -- it's not going to >be a one-time attack. > > - Bill > > >