Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Andy Bradford <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Thus said Jeff King on Sun, 01 Mar 2009 04:42:03 EST:

> For a single query, we expect the attacker to require around 2 billion
> packets.  For  a 10Mbps  link,  this  would  take  about 40  hours  of
> sustained attack. However, if the attacker triggers multiple identical
> queries, then  they require only  about 16 million  packets, requiring
> only 18 minutes on the same link.

Unless my math is wrong, that equates to about 13,888 packets per second
sustained  for 40  hours,  right?  That's a  lot  of  packets for  small
operations, and  would likely  be easily noticed.  For a  larger outfit,
that may not even show up as a blip.

> Your risk  may be amplified  if the attacker  can send packets  to you
> faster (because you have less time to respond). Your risk is amplified
> if  you have  patched  dnscache  to have  a  higher  value for  MAXUDP
> (because fewer packets are required).

And yet, the  more packets per second  that are sent, the  more risk the
attacker has in actually bringing down your infrastructure, or otherwise
triggering alarms. What is the likelyhood that something like this would
go unnoticed?

> Dean insists that  the expected number of packets with  this attack is
> actually 28 million. I think his math is suspect. See:

28 million within what period of time?

Andy
-- 
[-----------[system uptime]--------------------------------------------]
  9:14pm  up  1:31,  1 user,  load average: 1.20, 1.14, 1.10
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.