Re: Re: RR checks to avoid DoS attacks

"Dondeti, Lakshminath" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Tero Kivinen wrote:

>Dondeti, Lakshminath writes:
>  
>
>>Consider the notion of the cost of the attack to the attacker vs. the 
>>cost to the victim.  So the attacker needs to buy a prepaid SIM card to 
>>subscribe to a VoD service provided via IPsec protection, and then have 
>>the stream be re-directed at the victim.  To me that seems like an 
>>implausible scenario.  There are other simpler ways to launch a DoS attack.
>>    
>>
>
>Also if the victim, sends any ICMP port unreachable, or IKEv2
>unencrypted notify messages, the flood will stop after some time, as
>the sender will start and fail the dead peer detection for the victims
>address. 
>
>  
>
>>If the said DoS attacks are the only reason for RR checks in IKE based 
>>signaling of mobility, I think that part of the protocol should be optional.
>>    
>>
>
>BTW, the gateway will also know if there is high speed flow going to
>the client, so it can base the policy to do the RR on that fact. So it
>would do the RR always if the authentication is for some reason weak
>(i.e. for oppurtunistic encryption etc), or if there is high volume
>traffic going to the client (i.e. video server would always do those
>etc).
>  
>

Indeed.  The GW could make the decision based on its local policy, which 
could be

1.  RR is always enabled
2.  RR enabled for connections where clients used weak/anonymous 
authentication methods
3.  RR, if there is only one-way traffic for extended (defined locally) 
periods
and so on.

regards,
Lakshminath
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.