Re: RR checks to avoid DoS attacks

Tero Kivinen <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Dondeti, Lakshminath writes:
> Consider the notion of the cost of the attack to the attacker vs. the 
> cost to the victim.  So the attacker needs to buy a prepaid SIM card to 
> subscribe to a VoD service provided via IPsec protection, and then have 
> the stream be re-directed at the victim.  To me that seems like an 
> implausible scenario.  There are other simpler ways to launch a DoS attack.

Also if the victim, sends any ICMP port unreachable, or IKEv2
unencrypted notify messages, the flood will stop after some time, as
the sender will start and fail the dead peer detection for the victims
address. 

> If the said DoS attacks are the only reason for RR checks in IKE based 
> signaling of mobility, I think that part of the protocol should be optional.

BTW, the gateway will also know if there is high speed flow going to
the client, so it can base the policy to do the RR on that fact. So it
would do the RR always if the authentication is for some reason weak
(i.e. for oppurtunistic encryption etc), or if there is high volume
traffic going to the client (i.e. video server would always do those
etc).
-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.