Re: RR checks to avoid DoS attacks

"Dondeti, Lakshminath" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Consider the notion of the cost of the attack to the attacker vs. the 
cost to the victim.  So the attacker needs to buy a prepaid SIM card to 
subscribe to a VoD service provided via IPsec protection, and then have 
the stream be re-directed at the victim.  To me that seems like an 
implausible scenario.  There are other simpler ways to launch a DoS attack.

If the said DoS attacks are the only reason for RR checks in IKE based 
signaling of mobility, I think that part of the protocol should be optional.

best regards,
Lakshminath

Bill Sommerfeld wrote:

>>I contend that the attacker has no incentive to carry on the attack
>>after authenticating itself to a server that is going to be
>>encrypting all that traffic.
>>    
>>
>
>If the authenticated identity is disposable -- if it comes from the
>equivalent of a prepaid SIM card bought for cash -- it's not going to
>be a one-time attack.
>
>						 - Bill
>
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.