Spoofing and SCTP ADD-IP (was Re: Solving the right problems ...)

Pekka Nikander <pekka.nikander@nomadiclab.com> Mon, 15 September 2003 17:53 UTC

Received: from asgard.ietf.org (asgard.ietf.org [10.27.6.40]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA15216 for <ietf-web-archive@odin.ietf.org>; Mon, 15 Sep 2003 13:53:36 -0400 (EDT)
Received: from majordomo by asgard.ietf.org with local (Exim 4.14) id 19yxQB-0003EN-Jz for ietf-list@asgard.ietf.org; Mon, 15 Sep 2003 13:45:55 -0400
Received: from ietf.org ([10.27.2.28]) by asgard.ietf.org with esmtp (Exim 4.14) id 19yxPp-0003Bp-He for ietf@asgard.ietf.org; Mon, 15 Sep 2003 13:45:33 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14576; Mon, 15 Sep 2003 13:45:27 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19yxPo-0002lC-00; Mon, 15 Sep 2003 13:45:32 -0400
Received: from teldanex.hiit.fi ([212.68.5.99] helo=n97.nomadiclab.com) by ietf-mx with esmtp (Exim 4.12) id 19yxPn-0002ke-00; Mon, 15 Sep 2003 13:45:32 -0400
Received: from nomadiclab.com (polle.local.nikander.com [192.168.0.193]) by n97.nomadiclab.com (Postfix) with ESMTP id DB5591C; Mon, 15 Sep 2003 20:58:23 +0300 (EEST)
Message-ID: <3F65FA9E.2010801@nomadiclab.com>
Date: Mon, 15 Sep 2003 20:45:02 +0300
From: Pekka Nikander <pekka.nikander@nomadiclab.com>
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.5b) Gecko/20030827
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "Randall R. Stewart (home)" <randall@stewart.chicago.il.us>
Cc: ietf@ietf.org, ipv6@ietf.org
Subject: Spoofing and SCTP ADD-IP (was Re: Solving the right problems ...)
References: <3F6239E0.8090001@stewart.chicago.il.us> <01df01c36a7b$840dbb80$63124104@eagleswings> <3F61EAC2.7020304@stewart.chicago.il.us> <20030912165739.50b3866b.moore@cs.utk.edu> <3F6239E0.8090001@stewart.chicago.il.us> <5.2.0.9.2.20030913095009.0301ea40@pop.mcilink.com> <3F6373FD.1020308@stewart.chicago.il.us>
In-Reply-To: <3F6373FD.1020308@stewart.chicago.il.us>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: owner-ietf@ietf.org
Precedence: bulk
Content-Transfer-Encoding: 7bit

vinton g. cerf wrote:
>> We would also want to look very carefully at the potential spoofing 
>> opportunity that rebinding would likely introduce.

Randall R. Stewart (home) wrote:
> This is one of the reasons the authors of ADD-IP have NOT pushed to get 
> it done.. some more
> work needs to be done on this area...

http://www.ietf.org/internet-drafts/draft-nikander-mobileip-v6-ro-sec-01.txt
is a background document, produced by the MIPv6 route optimization
security design team, that tries to explain the security desing
in MIPv6 RO.  I think that most of the threats and much of the solution
model would most probably apply also to SCTP ADD-IP and, of course,
also other multi-address multi-homing solutions.

--Pekka Nikander