Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Sami Vaarala <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Hi,

Francis Dupont wrote:
>    return routability check that force the attacker to stay there
>    to continue the attack forever.
>    
> => yes, mobile ip and mobike have different weapons. My concern is
> they share the same issue but the WGs react in very different ways.

A quick comment:  if the attacker stays on the path, doing NAT
forever (i.e. allows peers to exchange packets), then it's not
really an attack.  It's just plain NAT.

At least in the MIPv4 context this becomes a relevant attack
*only* if the attacker (a) intervenes in the binding establishment
stage (acting as a NAT), and (b) then leaves the path.  The result
is either a defunct binding or a traffic flow redirected to a
victim.  If the attacker stays on and continues to perform the
NAT function, traffic flow is not changed.

Is there a difference in MOBIKE?  I.e. is this an attack if the
attacker stays on the path?

Best,

-Sami
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.