Re: Re: RR checks to avoid DoS attacks

"Dondeti, Lakshminath" <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Jari Arkko wrote:

> Tero Kivinen wrote:
>
>>> Personally I think it would be also acceptable to do the RR check 
>>> after changing the address. That is, the gateway updates the SAs 
>>> immediately, but then sends a separate informational exchange 
>>> containing some kind of cookie. What do others think
>>> about this?
>>
>>
>>
>> I would think that would be ok, for most of the scenarios. In some
>> cases (completely unauthenticated connection to video stream server)
>> could put the traffic on hold while waiting the RR to succeed, but
>> that would be local matter.
>
>
> This would be pretty good, but personally, I still think it
> would be both simpler and more secure to do the RR first.
>
> Regarding simplicity, I'd like to avoid introducing too
> many additional parameters or configuration, so I'd
> rather have the MOBIKE RFC specify when the exchange
> needs to be done than make it configurable. Regarding
> security, the issue is amplification, some of which will
> still be possible during the timeout period for the RR test.
> We should also remember that the folks who need to decide
> whether to require a strict RR test before moving the flow
> are not the same ones as the potential victims.
>
> --Jari
>
The remote access GW - which can initiate the RR test at will -  would 
be affected more than the victim, right?

Lakshminath
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.