Re: Question regarding RFC 4960 Out of the Blue packets

"Horsham, Ian" <[email protected]> Thu, 13 Oct 2011 17:02:47 +0100
Newsgroups gmane.ietf.sigtran
Message-ID <3ED1C61A16C32D46A98E05BFBA5F40B306E869B4@GBCWSWIEM001.ad.plc.cwintra.com>
Hi Jeff

I understand now thanks (at last I hear you cry)! 

1. If a packet comes from an endpoint which it has an association with
the packet is silently discarded (to protect against attack).
2. If the packet come from an endpoint which it hasn't got an
association with the packet is OOTB.

I was thinking that the definition of an association would include
having a valid verification tag. Apologies for this misunderstanding.

Thank you Jeff, Michael and Arif for responding to my questions. You
have been very helpful.

Many Thanks
Ian





-----Original Message-----
From: Jeff Morriss [mailto:[email protected]] 
Sent: 13 October 2011 15:43
To: Horsham, Ian
Cc: [email protected]
Subject: Re: [Sigtran] Question regarding RFC 4960 Out of the Blue
packets



Horsham, Ian wrote:

[BTW, SCTP is usually discussed over on the tsvwg list now.]

> Section 1.5.6 only says "Packets received without the expected 
> Verification Tag value are discarded" (it doesn't actually state that 
> they are silently discarded). It does go on to say that "The receiver 
> of an SCTP packet with an invalid CRC32c checksum silently discards 
> the packet.". However I'm considering a packet with a correct CRC32c 
> check and an incorrect verification tag.
> 
> This has made me think that there is a difference between invalid 
> packets (CRC32c error) and OOTB packets (CRC32c passed but 
> verification tag incorrect) and that is why section 8.4 exists.
> 
> Do you think that section 8.4 can be ignored or is there a difference 
> between invalid packets and OOTB packets? I think that there is a 
> difference and the RFC is saying that OOTB packets should be handled 
> differently (as per section 8.4).
> 
> Consequently, I can see the benefits of silently discarding these 
> packets (for security).

Maybe this explanation helps:

Section 1.5.6's guidance to discard packets with "unexpected" vtags only

applies when the receiver of the packet has a matching (based on the 
addresses) association.  So, in Michael's words, the receiver has an 
expectation as to what the vtag should be and the packet does not match
it.

OOTB, on the other hand, applies to packets for which the receiver has 
no association.

You shouldn't send an ABORT in the "unexpected" case to avoid aborting a

valid association due to a lucky hit on a blind masquerade attack or 
because a (very late) packet from a previous instance of that 
association arrived.

You should send an ABORT (as per section 8.4) to correct a peer who 
seems to think you have an association that you don't have.

This e-mail has been scanned for viruses by the Cable&Wireless Worldwide e-mail security system. For more information on a proactive 
managed e-mail secure service, visit http://www.cw.com/managed-exchange

The information contained in this e-mail is confidential and may also be subject to legal privilege. It is intended only for the recipient(s) named above. 
If you are not named above as a recipient, you must not read, copy, disclose, forward or otherwise use the information contained in this email. If you 
have received this e-mail in error, please notify the sender (whose contact details are above) immediately by reply e-mail and delete the message and any 
attachments without retaining any copies.

Cable & Wireless Worldwide plc 
Registered in England and Wales. Company Number 07029206
Registered office: Liberty House, 76 Hammersmith Road, London W14 8UD, England