Re: RR checks to avoid DoS attacks

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Jari Arkko wrote:
>
> This would be pretty good, but personally, I still think it
> would be both simpler and more secure to do the RR first.
> 
> Regarding simplicity, I'd like to avoid introducing too
> many additional parameters or configuration, so I'd
> rather have the MOBIKE RFC specify when the exchange
> needs to be done than make it configurable. Regarding
> security, the issue is amplification, some of which will
> still be possible during the timeout period for the RR test.
> We should also remember that the folks who need to decide
> whether to require a strict RR test before moving the flow
> are not the same ones as the potential victims.

I agree that simplicity is good thing... however, I did
some sketching about this, and haven't yet found anything
that actually works. The "most obvious" (to me, at least)
and simple ways of doing RR first seem to interact badly 
with path failover and/or IKEv2 window size and/or normal 
IKEv2 retransmissions.

So suggestions on how to do with are very welcome..

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.