Re: RR checks to avoid DoS attacks
Tero Kivinen <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Dondeti, Lakshminath writes: > Consider the notion of the cost of the attack to the attacker vs. the > cost to the victim. So the attacker needs to buy a prepaid SIM card to > subscribe to a VoD service provided via IPsec protection, and then have > the stream be re-directed at the victim. To me that seems like an > implausible scenario. There are other simpler ways to launch a DoS attack. Also if the victim, sends any ICMP port unreachable, or IKEv2 unencrypted notify messages, the flood will stop after some time, as the sender will start and fail the dead peer detection for the victims address. > If the said DoS attacks are the only reason for RR checks in IKE based > signaling of mobility, I think that part of the protocol should be optional. BTW, the gateway will also know if there is high speed flow going to the client, so it can base the policy to do the RR on that fact. So it would do the RR always if the authentication is for some reason weak (i.e. for oppurtunistic encryption etc), or if there is high volume traffic going to the client (i.e. video server would always do those etc). -- [email protected]