Re: SCTP: Heartbeat ack recieved without sending Heartbeat

radhika agarwal <[email protected]>
Newsgroups gmane.ietf.sigtran
Message-ID <[email protected]>
Hi,
   
  If an OOTB heartbeat ack is received, then it shall anyways lead to sending of an abort chunk to the peer, as per section 8.4 of RFC 2960.
   
  If an heartbeat ack chunk is received from a destination addr of a valid association, to which no heartbeat was sent, then the heartbeat ack msg should be discarded. 
   
  The processing of such a heartbeat ack message may lead to incorrect calculations of association parameters like RTT
   
  Michael, as for peer sending an incorrect HB info , dont we assume that the peer with which the 4 way handshake is successfully executed is not an attacker. If not then we might have to include another MAC with the HB info field.
   
  Regards,
  Radhika
   
  


Michael Tuexen <[email protected]> wrote:
  Comments in-line,
Best regards
Michael

On Jun 16, 2006, at 12:18 PM, Brian F. G. Bidulock wrote:

> ash,
>
> See also RFC 4460 Section 2.36.
That section describes initial path verification. I think his question
was more general: How do you process a received HB-ACK, when you
have never sent a HB?
The other point I made was: Even if you sent a HB, you can not be
sure that the peer reflects the HB info. It could be an attacker...
(we did this years ago at an interop and this provided some 
implementations
problems...)
>
> --brian
>
> _______________________________________________
> Sigtran mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/sigtran
>


_______________________________________________
Sigtran mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/sigtran



 
 
 
 
 
 
 
 
_______________________________________________________________
Life is Beautiful.
______________________________________________________________

 		
---------------------------------
Yahoo! Messenger with Voice. Make PC-to-Phone Calls to the US (and 30+ countries) for 2¢/min or less.

_______________________________________________
Sigtran mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/sigtran
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.