Re: Question regarding RFC 4960 Out of the Blue packets
"Horsham, Ian" <[email protected]> Thu, 13 Oct 2011 17:02:47 +0100
| Newsgroups | gmane.ietf.sigtran |
|---|---|
| Message-ID | <3ED1C61A16C32D46A98E05BFBA5F40B306E869B4@GBCWSWIEM001.ad.plc.cwintra.com> |
Hi Jeff I understand now thanks (at last I hear you cry)! 1. If a packet comes from an endpoint which it has an association with the packet is silently discarded (to protect against attack). 2. If the packet come from an endpoint which it hasn't got an association with the packet is OOTB. I was thinking that the definition of an association would include having a valid verification tag. Apologies for this misunderstanding. Thank you Jeff, Michael and Arif for responding to my questions. You have been very helpful. Many Thanks Ian -----Original Message----- From: Jeff Morriss [mailto:[email protected]] Sent: 13 October 2011 15:43 To: Horsham, Ian Cc: [email protected] Subject: Re: [Sigtran] Question regarding RFC 4960 Out of the Blue packets Horsham, Ian wrote: [BTW, SCTP is usually discussed over on the tsvwg list now.] > Section 1.5.6 only says "Packets received without the expected > Verification Tag value are discarded" (it doesn't actually state that > they are silently discarded). It does go on to say that "The receiver > of an SCTP packet with an invalid CRC32c checksum silently discards > the packet.". However I'm considering a packet with a correct CRC32c > check and an incorrect verification tag. > > This has made me think that there is a difference between invalid > packets (CRC32c error) and OOTB packets (CRC32c passed but > verification tag incorrect) and that is why section 8.4 exists. > > Do you think that section 8.4 can be ignored or is there a difference > between invalid packets and OOTB packets? I think that there is a > difference and the RFC is saying that OOTB packets should be handled > differently (as per section 8.4). > > Consequently, I can see the benefits of silently discarding these > packets (for security). Maybe this explanation helps: Section 1.5.6's guidance to discard packets with "unexpected" vtags only applies when the receiver of the packet has a matching (based on the addresses) association. So, in Michael's words, the receiver has an expectation as to what the vtag should be and the packet does not match it. OOTB, on the other hand, applies to packets for which the receiver has no association. You shouldn't send an ABORT in the "unexpected" case to avoid aborting a valid association due to a lucky hit on a blind masquerade attack or because a (very late) packet from a previous instance of that association arrived. You should send an ABORT (as per section 8.4) to correct a peer who seems to think you have an association that you don't have. This e-mail has been scanned for viruses by the Cable&Wireless Worldwide e-mail security system. For more information on a proactive managed e-mail secure service, visit http://www.cw.com/managed-exchange The information contained in this e-mail is confidential and may also be subject to legal privilege. It is intended only for the recipient(s) named above. If you are not named above as a recipient, you must not read, copy, disclose, forward or otherwise use the information contained in this email. If you have received this e-mail in error, please notify the sender (whose contact details are above) immediately by reply e-mail and delete the message and any attachments without retaining any copies. Cable & Wireless Worldwide plc Registered in England and Wales. Company Number 07029206 Registered office: Liberty House, 76 Hammersmith Road, London W14 8UD, England