Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Thu, 12 Feb 2009, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> > This appears to increase the vulnerability, particularly if the UDP
> > ports can be predicted because they don't change as often. In that case,
> > the attack is reduced to number of probable UDP ports * 64k packets to
> > run though the QIDs.
> 
> I'm not following you - what makes you think UDP ports won't change as
> often?

Before:
200 uncached queries, 200 udp ports consumed and 'returned to the Urn'.

After patch:
200 uncached queries, perhaps 1 udp port consumed.

With caching, Attacker makes one query that will hit its nameserver,
records the port, predicts the likely next port, runs an attack on that
+small n to account for a few unrelated queries.  Merging queries
results in less port use.

> > An important point was that Kevin's formula for Birthday attack was
> > wrong, as was their whole mathematical analysis.
> 
> Are you talking about the analysis in
> http://www.your.org/dnscache/djbdns.pdf, or something else?  Can you
> explain exactly where it goes wrong?

Kaminsky's formula and the correct formula are in two messages I sent
from DNSEXT.  There's a little more in offlist discussion from October,
where we talked about the mistakes he made; but the two messages I sent
detail the pertinent facts.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.