Re: [IPsec] Puzzles draft - another idea

Paul Wouters <paul@nohats.ca> Wed, 30 July 2014 19:03 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 403751A0366 for <ipsec@ietfa.amsl.com>; Wed, 30 Jul 2014 12:03:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cNQnV4-py524 for <ipsec@ietfa.amsl.com>; Wed, 30 Jul 2014 12:03:00 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A32C11A02F5 for <ipsec@ietf.org>; Wed, 30 Jul 2014 12:02:59 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 3FE4880048; Wed, 30 Jul 2014 15:02:57 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1406746977; bh=UiqY0R0jxE6o+cVHSeKSfEiZCCL/YOSxD71hIn3inoE=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=RIce8c+zDK/GRmNWdy1KBn+7vB5O6L9IufR1A2aJqiePzQySXl39Njm7GsA+hhZEC BNSheifXEhKQwv/hz7olaQqYf/FsQJar69Q0DEreYA+u8KTNzDOZWuEZV5De8zFwkg OJHswJowpJ/QTc0Xa0LY59uMDxZej9g2U0W1RYy8=
Received: from localhost (paul@localhost) by bofh.nohats.ca (8.14.7/8.14.7/Submit) with ESMTP id s6UJ2uED023212; Wed, 30 Jul 2014 15:02:56 -0400
X-Authentication-Warning: bofh.nohats.ca: paul owned process doing -bs
Date: Wed, 30 Jul 2014 15:02:56 -0400
From: Paul Wouters <paul@nohats.ca>
To: Yoav Nir <ynir.ietf@gmail.com>
In-Reply-To: <91340EE3-3DF4-4665-B21A-A108D00ADDE6@gmail.com>
Message-ID: <alpine.LFD.2.10.1407301457180.25462@bofh.nohats.ca>
References: <B163992F-EA91-49E9-B11C-AAF0DB6EB711@gmail.com> <53D911DD.1000801@gmail.com> <91340EE3-3DF4-4665-B21A-A108D00ADDE6@gmail.com>
User-Agent: Alpine 2.10 (LFD 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ipsec/JZ5rbjr1F_bUL1KF9xow0iZd2FI
Cc: ipsec <ipsec@ietf.org>
Subject: Re: [IPsec] Puzzles draft - another idea
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jul 2014 19:03:03 -0000

On Wed, 30 Jul 2014, Yoav Nir wrote:

> Suppose our half-open SA table can hold 100,000 entries and we clear them out after 10 seconds. That allows 10,000 entries per
> second. More realistic number are 18 bits for the iPhone and 20 bits for the attacker, so to block out those iPhones, the attacker
> would have to perform 10,000 * 2^20 SHA-256 hashes per second, or about 10 billion hashes. That’s about 400 server-class hardware
> working full-time, or a 10,000-way botnet. The draft is all about increasing the work for the attacker, and I believe this is doing
> it well. The baseline is sending 20,000 packets per second while only copying the cookie (no PK or hash operations at all).
> 
> It is possible to do as in the current draft, and set a single difficulty level (say, 18 bits). This allows the attacker a nice and
> deterministic way to keep the half-open SA table full, which blocks out all clients, not just the iPhones. 

The iphone (which is only rumored to do IKEv2 with iOS8 likely to be
released in September this year) currently has a
terrible record of continuously re-establishing connections. Like
whenever the screen saver hits it will tear down the tunnel. With
an always-on profile, that means if I unblanc the screen, it will
start a new IKE session.

A scheme like this would drain the battery on top of the current
re-establishing draining, that already prevents me from using an
always-on profile - my iphone won't last for 4 hours.

Perhaps we should look at other types of puzzles that do not depend on
raw CPU power?

Paul