Re: Re: RR checks to avoid DoS attacks

"Dondeti, Lakshminath" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Bill,

I am not saying that we ignore realistic DoS attacks, but I think this 
particular scenario we are examining is not a practical avenue for an 
attacker.  I feel strongly that the cost of the attack is sufficiently 
large for the attacker, and comfortable with not doing an RR.

If I am hand-waving in characterizing this particular attack you 
articulated as unrealistic, please make that case.  Thanks.

Also, please see inline:

Bill Sommerfeld wrote:

>>If the said DoS attacks are the only reason for RR checks in IKE based 
>>signaling of mobility, I think that part of the protocol should be optional.
>>    
>>
>
>The widespread deployment of nodes which can be exploited into
>performing DoS attacks on a third party victims is the single biggest
>security problem facing the current Internet.  
>
>  
>
I would say 'one of the problems,' but agreed in general.  It is not a 
problem however when the potential attacker is cryptographically 
authenticated to the entity that facilitates the attack and possibly 
incurs a higher cost ((the IPsec GW has to encrypt and encapsulate the 
packets, whereas the victim just drops them) than the targeted victim.

regards,
Lakshminath

>I would be most upset if we ended up deploying another such set of
>nodes as a result of this.
>
>We absolutely must examine each potential DoS attack; we cannot, as
>was once common, wave our hands and say that dealing with DoS attacks
>is impossible.
>
>						- Bill
>						
>
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.