Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]

"Ebalard, Arnaud" <Arnaud.Ebalard@eads.net> Mon, 30 April 2007 14:01 UTC

Return-path: <ipv6-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HiWRm-0003xb-Tx; Mon, 30 Apr 2007 10:01:46 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HiWRl-0003xV-1K for ipv6@ietf.org; Mon, 30 Apr 2007 10:01:45 -0400
Received: from ns1.its.eads.net ([193.56.40.66] helo=mx1.its.eads.net) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HiWRj-0000To-Kp for ipv6@ietf.org; Mon, 30 Apr 2007 10:01:45 -0400
Received: from fr-gate1.mailhub.intra.corp ([53.154.16.33]) by mx1.its.eads.net with Microsoft SMTPSVC(6.0.3790.2499); Mon, 30 Apr 2007 15:59:20 +0200
Received: from sfrsu800.hq.corp ([10.21.8.22]) by fr-gate1.mailhub.intra.corp with Microsoft SMTPSVC(5.0.2195.6713); Mon, 30 Apr 2007 16:04:37 +0200
Received: from [172.16.23.99] (10.251.5.23 [10.251.5.23]) by gecko.hq.corp with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2657.72) id H92ZLCJC; Mon, 30 Apr 2007 16:11:38 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-MimeOLE: Produced By Microsoft Exchange V6.5
X-Mailer: Apple Mail (2.752.2)
Content-class: urn:content-classes:message
Date: Mon, 30 Apr 2007 16:01:33 +0200
Message-ID: <F1D2C759-0DF4-4BA9-B72E-26AE02A7F9C9@eads.net>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]
Thread-Index: AceLMXhjbte8JFd4RR6vy97tZbM6Sw==
From: "Ebalard, Arnaud" <Arnaud.Ebalard@eads.net>
To: pars.mutaf@int-evry.fr
X-OriginalArrivalTime: 30 Apr 2007 14:04:37.0734 (UTC) FILETIME=[7D20C860:01C78B30]
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 4adaf050708fb13be3316a9eee889caa
Cc: IETF IPv6 Mailing List <ipv6@ietf.org>
Subject: Re: Question for IPv6 w.g. on [Re: IPv6 Type 0 Routing Headerissu es]
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "IP Version 6 Working Group \(ipv6\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
Errors-To: ipv6-bounces@ietf.org

Le 30 avr. 07 à 14:28, Pars Mutaf a écrit :

>>>  - how many hops you can make w/ a packet sized 1280?
>
> Maybe I'm missing something, but the attacker wouldn't
> rather send millions of *very small* packets (to keep the
> routers busy) instead sending elephants??

This morning, just to test it on a Mac Mini, i pushed a little more  
than 1MB/s of such RH0 packets (those you call "elephants") between a  
Linux box (forwarding activated, pre 2.6.20.9) and the Mac (both  
gigabit, directly connected). This is slide 35/57 of the  
presentation. The Bandwidth monitor output on the Linux is below  
(same on the Mac) :

Bandwidth Monitor 1.1.0

        Iface        RX(KB/sec)   TX(KB/sec)   Total(KB/sec)

         eth0        45512.315    46102.463       91614.778
           lo            0.985        0.985           1.970

[...]



I can ensure you that when you are limited by your upload bandwidth,  
and only with few KB/s, you simply saturate a 100Mbit/s Ethernet link.

When you send millions of packets at X KB/s, the routers still have  
to cope with that amount of bandwidth (X KB/s). "Elephants" simply  
amplify your bandwidth between the 2 routers (44*X KB/s upload and  
44*X KB/s download, as if there were almost 90 people like you on the  
link).

Cheers,

a+

ps : 44 is the number of pairs of @ (rtr1, rtr2) in the RH0.

-- Arnaud Ebalard
EADS Innovation Works - IT Sec Research Engineer
PGP KeyID:047A5026 FingerPrint:47EB85FEB99AAB85FD0946F30255957C047A5026


--------------------------------------------------------------------
IETF IPv6 working group mailing list
ipv6@ietf.org
Administrative Requests: https://www1.ietf.org/mailman/listinfo/ipv6
--------------------------------------------------------------------