[MEXT] Invitation to humanresolvers ML (was: Re: Energy consumption attacks)

Pars Mutaf <[email protected]>
Newsgroups gmane.ietf.nemo
Message-ID <[email protected]>
Hi Julien, all,

We have a mailing list (humanresolvers) that was initially created to work
on the
higher level spam attacks on low-end mobile IP devices that consume host
resources
e.g. energy, CPU and memory, and annoy the user. We can expand the problem
scope
to primarily work on the IP-layer energy consuming Denial-of-Service (DoS)
attacks that
consist of sending large number of IP spoofing malicious packets to a victim
without
opening valid sessions (see description below). New attacks may also be
discovered.

The mailing list address is as follows:

https://www.ietf.org/mailman/listinfo/humanresolvers

Problem statement:
==============

Battery powered mobile IP hosts will probably be victim of new
Denial-of-Service (DoS)
attacks that consume limited host resources e.g. energy, CPU and memory. An
attacker
can remotely consume victim mobile hosts' battery by continuously sending
them bogus
session initiating packets e.g. SIP INTIVE or TCP SYN. A simple defense e.g.
attempting
to drop malicious packets would result in mobile host unreachability, since
the victim
cannot possibly differentiate between legitimate and malicious session
initiating packets
purportedly coming from random IP addresses.

When under attack, a victim will consume energy for:

- Receiving the messages (continuously waking up from sleep mode)
- Processing them and preparing reply packets (L2 and L3)
- Sending replies (L2 ACKs and upper layer replies e.g. SIP or TCP replies)

Serious design efforts are being made in MAC layer access technologies to
enable energy
conserving sleep mode. The attack would not only foil these efforts, but
also consume energy
by "forcing" the victim to send replies to frequent malicious packets
purportedly coming from
random IP addresses. For example, simple experiments show that the battery
of a mobile
phone with 802.11 access can be remotely consumed in ~3 hours (full battery,
1350 mAh).
The attack may shut down the victim device more quickly if its battery level
is low. Attacks
on phones using an outdoor technology would result in faster energy
consumption due to the
longer distances to the base station.

At a higher level, attackers can also organize spamming attacks that consume
victims'
resources and annoy the users by sending spam.

I would like to invite interested folks to subscribe to discuss these
problems.

Regards,

Pars


On Tue, Mar 22, 2011 at 5:39 PM, Julien Laganier <[email protected]>wrote:

> Hello Pars,
>
> I can agree that the topic can be of interest to the MIPv6 community
> and thus it would be appropriate to post on the list a pointer to a
> place where the topic is being discussed. However since the attacks
> are generic and not specific to the MIPv6 protocol suite, I believe
> discussions on the topic itself are out-of-scope for this mailing
> list.
>
> Thanks,
>
> --julien
>
> On Tue, Mar 22, 2011 at 1:59 AM, Pars Mutaf <[email protected]> wrote:
> > Hi Julien,
> >
> > MIPv6 is mostly about battery powered mobile hosts, so I think this topic
> > should be of interest to Mobile IPv6 community. Secondly, when you think
> > about solutions, you may realize that it is an IP layer problem. Any
> upper
> > layer host identifier (FQDN or SIP URI etc) would be resolved to the
> "fixed"
> > home address of the mobile host and once the attacker has learned it, the
> > attack is possible. The attacker can remotely consume the victim's
> energy.
> > Application layer solutions like spam filtering would be useless because
> the
> > attacker is simply sending bogus packets, not even opening sessions.
> >
> > In fact, we may expand the problem space since there may be other
> problems
> > due to having a fixed MIPv6 home address. But I think the remote energy
> > consumption attack is the most serious one. Serious design efforts are
> being
> > made at MAC layer to enable energy conserving sleep mode. The attack
> would
> > not only foil these efforts, but also consume energy by "forcing" the
> victim
> > to reply to frequent malicious packets purportedly coming from random IP
> > addresses.
> >
> > Thanks,
> >
> > Pars
> >
> > On Tue, Mar 22, 2011 at 5:27 AM, Julien Laganier <[email protected]>
> > wrote:
> >>
> >> Pars -
> >>
> >> How is this attack related to MIPv6?
> >>
> >> --julien
> >>
> >> On Mon, Mar 21, 2011 at 2:43 AM, Pars Mutaf <[email protected]>
> wrote:
> >> > Hello,
> >> >
> >> > I was wondering if solutions to energy consumption attacks on battery
> >> > powered mobile hosts would be of interest to IETF Mobile IPv6
> community.
> >> >
> >> > The attack consists of sending frequent request packets e.g. SIP
> INVITE
> >> > or
> >> > TCP SYN to a victim's home address.
> >> >
> >> > For example, experiments showed that the battery of a mobile phone
> with
> >> > 802.11 access can be remotely consumed in 3 hours (full battery).
> >> > Attacks on
> >> > phones using an outdoor technology would result in more energy
> >> > consumption
> >> > because of the longer distance to the base station.
> >> >
> >> > The victim becomes unusable.
> >> >
> >> > Regards,
> >> >
> >> > Pars
> >> >
> >> > _______________________________________________
> >> > MEXT mailing list
> >> > [email protected]
> >> > https://www.ietf.org/mailman/listinfo/mext
> >> >
> >> >
> >
> >
>

_______________________________________________
MEXT mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.