Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   A quick comment:  if the attacker stays on the path, doing NAT
   forever (i.e. allows peers to exchange packets), then it's not
   really an attack.  It's just plain NAT.
   
=> what I call the transient pseudo-NAT differs from a real NAT on:
 - it stays on the path only for the attack (transient)
 - it modifies only some packets belonging to a signaling protocol
 - it redirects a large bunch of traffic controlled by this signaling
   protocol.

   At least in the MIPv4 context this becomes a relevant attack
   *only* if the attacker (a) intervenes in the binding establishment
   stage (acting as a NAT), and (b) then leaves the path.

=> yes, this is the idea. One unpleasant property is the attack works
better if the signaling is more efficient (i.e., uses less messages).

   The result
   is either a defunct binding or a traffic flow redirected to a
   victim.  If the attacker stays on and continues to perform the
   NAT function, traffic flow is not changed.
   
=> the attack I describe is not the bogus NAT one. In mine
a small action has a great effect.

   Is there a difference in MOBIKE?

=> there is no real difference between IKE and MIP, both are signaling
which can be attacked as soon as NAT traversal is enabled.

   I.e. is this an attack if the attacker stays on the path?
   
=> yes but this is a different one.

BTW the implicit update of NAT traversal is a good defense against the
attack: as soon as a packet from the end behind the NAT is not modified,
its peer jumps to the right address. This is one of the reasons I believe
the SHOULD for the implicit update can be made stronger.

Regards

[email protected]

PS: I explain the attack in draft-dupont-transient-pseudonat-04.txt
(expired because my interest is not in the attack itself but to get
proper defense in signalings).
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.