Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]
"Ebalard, Arnaud" <Arnaud.Ebalard@eads.net> Mon, 30 April 2007 14:01 UTC
Return-path: <ipv6-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HiWRm-0003xb-Tx; Mon, 30 Apr 2007 10:01:46 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HiWRl-0003xV-1K for ipv6@ietf.org; Mon, 30 Apr 2007 10:01:45 -0400
Received: from ns1.its.eads.net ([193.56.40.66] helo=mx1.its.eads.net) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HiWRj-0000To-Kp for ipv6@ietf.org; Mon, 30 Apr 2007 10:01:45 -0400
Received: from fr-gate1.mailhub.intra.corp ([53.154.16.33]) by mx1.its.eads.net with Microsoft SMTPSVC(6.0.3790.2499); Mon, 30 Apr 2007 15:59:20 +0200
Received: from sfrsu800.hq.corp ([10.21.8.22]) by fr-gate1.mailhub.intra.corp with Microsoft SMTPSVC(5.0.2195.6713); Mon, 30 Apr 2007 16:04:37 +0200
Received: from [172.16.23.99] (10.251.5.23 [10.251.5.23]) by gecko.hq.corp with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2657.72) id H92ZLCJC; Mon, 30 Apr 2007 16:11:38 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-MimeOLE: Produced By Microsoft Exchange V6.5
X-Mailer: Apple Mail (2.752.2)
Content-class: urn:content-classes:message
Date: Mon, 30 Apr 2007 16:01:33 +0200
Message-ID: <F1D2C759-0DF4-4BA9-B72E-26AE02A7F9C9@eads.net>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]
Thread-Index: AceLMXhjbte8JFd4RR6vy97tZbM6Sw==
From: "Ebalard, Arnaud" <Arnaud.Ebalard@eads.net>
To: pars.mutaf@int-evry.fr
X-OriginalArrivalTime: 30 Apr 2007 14:04:37.0734 (UTC) FILETIME=[7D20C860:01C78B30]
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 4adaf050708fb13be3316a9eee889caa
Cc: IETF IPv6 Mailing List <ipv6@ietf.org>
Subject: Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "IP Version 6 Working Group \(ipv6\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
Errors-To: ipv6-bounces@ietf.org
Le 30 avr. 07 à 14:28, Pars Mutaf a écrit : >>> - how many hops you can make w/ a packet sized 1280? > > Maybe I'm missing something, but the attacker wouldn't > rather send millions of *very small* packets (to keep the > routers busy) instead sending elephants?? This morning, just to test it on a Mac Mini, i pushed a little more than 1MB/s of such RH0 packets (those you call "elephants") between a Linux box (forwarding activated, pre 2.6.20.9) and the Mac (both gigabit, directly connected). This is slide 35/57 of the presentation. The Bandwidth monitor output on the Linux is below (same on the Mac) : Bandwidth Monitor 1.1.0 Iface RX(KB/sec) TX(KB/sec) Total(KB/sec) eth0 45512.315 46102.463 91614.778 lo 0.985 0.985 1.970 [...] I can ensure you that when you are limited by your upload bandwidth, and only with few KB/s, you simply saturate a 100Mbit/s Ethernet link. When you send millions of packets at X KB/s, the routers still have to cope with that amount of bandwidth (X KB/s). "Elephants" simply amplify your bandwidth between the 2 routers (44*X KB/s upload and 44*X KB/s download, as if there were almost 90 people like you on the link). Cheers, a+ ps : 44 is the number of pairs of @ (rtr1, rtr2) in the RH0. -- Arnaud Ebalard EADS Innovation Works - IT Sec Research Engineer PGP KeyID:047A5026 FingerPrint:47EB85FEB99AAB85FD0946F30255957C047A5026 -------------------------------------------------------------------- IETF IPv6 working group mailing list ipv6@ietf.org Administrative Requests: https://www1.ietf.org/mailman/listinfo/ipv6 --------------------------------------------------------------------
- Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Ro… Ebalard, Arnaud
- Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Ro… Jeroen Massar
- Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Ro… Ebalard, Arnaud