[MEXT] Invitation to humanresolvers ML (was: Re: Energy consumption attacks)
Pars Mutaf <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <[email protected]> |
Hi Julien, all, We have a mailing list (humanresolvers) that was initially created to work on the higher level spam attacks on low-end mobile IP devices that consume host resources e.g. energy, CPU and memory, and annoy the user. We can expand the problem scope to primarily work on the IP-layer energy consuming Denial-of-Service (DoS) attacks that consist of sending large number of IP spoofing malicious packets to a victim without opening valid sessions (see description below). New attacks may also be discovered. The mailing list address is as follows: https://www.ietf.org/mailman/listinfo/humanresolvers Problem statement: ============== Battery powered mobile IP hosts will probably be victim of new Denial-of-Service (DoS) attacks that consume limited host resources e.g. energy, CPU and memory. An attacker can remotely consume victim mobile hosts' battery by continuously sending them bogus session initiating packets e.g. SIP INTIVE or TCP SYN. A simple defense e.g. attempting to drop malicious packets would result in mobile host unreachability, since the victim cannot possibly differentiate between legitimate and malicious session initiating packets purportedly coming from random IP addresses. When under attack, a victim will consume energy for: - Receiving the messages (continuously waking up from sleep mode) - Processing them and preparing reply packets (L2 and L3) - Sending replies (L2 ACKs and upper layer replies e.g. SIP or TCP replies) Serious design efforts are being made in MAC layer access technologies to enable energy conserving sleep mode. The attack would not only foil these efforts, but also consume energy by "forcing" the victim to send replies to frequent malicious packets purportedly coming from random IP addresses. For example, simple experiments show that the battery of a mobile phone with 802.11 access can be remotely consumed in ~3 hours (full battery, 1350 mAh). The attack may shut down the victim device more quickly if its battery level is low. Attacks on phones using an outdoor technology would result in faster energy consumption due to the longer distances to the base station. At a higher level, attackers can also organize spamming attacks that consume victims' resources and annoy the users by sending spam. I would like to invite interested folks to subscribe to discuss these problems. Regards, Pars On Tue, Mar 22, 2011 at 5:39 PM, Julien Laganier <[email protected]>wrote: > Hello Pars, > > I can agree that the topic can be of interest to the MIPv6 community > and thus it would be appropriate to post on the list a pointer to a > place where the topic is being discussed. However since the attacks > are generic and not specific to the MIPv6 protocol suite, I believe > discussions on the topic itself are out-of-scope for this mailing > list. > > Thanks, > > --julien > > On Tue, Mar 22, 2011 at 1:59 AM, Pars Mutaf <[email protected]> wrote: > > Hi Julien, > > > > MIPv6 is mostly about battery powered mobile hosts, so I think this topic > > should be of interest to Mobile IPv6 community. Secondly, when you think > > about solutions, you may realize that it is an IP layer problem. Any > upper > > layer host identifier (FQDN or SIP URI etc) would be resolved to the > "fixed" > > home address of the mobile host and once the attacker has learned it, the > > attack is possible. The attacker can remotely consume the victim's > energy. > > Application layer solutions like spam filtering would be useless because > the > > attacker is simply sending bogus packets, not even opening sessions. > > > > In fact, we may expand the problem space since there may be other > problems > > due to having a fixed MIPv6 home address. But I think the remote energy > > consumption attack is the most serious one. Serious design efforts are > being > > made at MAC layer to enable energy conserving sleep mode. The attack > would > > not only foil these efforts, but also consume energy by "forcing" the > victim > > to reply to frequent malicious packets purportedly coming from random IP > > addresses. > > > > Thanks, > > > > Pars > > > > On Tue, Mar 22, 2011 at 5:27 AM, Julien Laganier <[email protected]> > > wrote: > >> > >> Pars - > >> > >> How is this attack related to MIPv6? > >> > >> --julien > >> > >> On Mon, Mar 21, 2011 at 2:43 AM, Pars Mutaf <[email protected]> > wrote: > >> > Hello, > >> > > >> > I was wondering if solutions to energy consumption attacks on battery > >> > powered mobile hosts would be of interest to IETF Mobile IPv6 > community. > >> > > >> > The attack consists of sending frequent request packets e.g. SIP > INVITE > >> > or > >> > TCP SYN to a victim's home address. > >> > > >> > For example, experiments showed that the battery of a mobile phone > with > >> > 802.11 access can be remotely consumed in 3 hours (full battery). > >> > Attacks on > >> > phones using an outdoor technology would result in more energy > >> > consumption > >> > because of the longer distance to the base station. > >> > > >> > The victim becomes unusable. > >> > > >> > Regards, > >> > > >> > Pars > >> > > >> > _______________________________________________ > >> > MEXT mailing list > >> > [email protected] > >> > https://www.ietf.org/mailman/listinfo/mext > >> > > >> > > > > > > _______________________________________________ MEXT mailing list [email protected] https://www.ietf.org/mailman/listinfo/mext