Re: [shara] port randomization (draft-ymbk-aplusp-03)

"Dan Wing" <dwing@cisco.com> Thu, 12 March 2009 17:34 UTC

Return-Path: <dwing@cisco.com>
X-Original-To: shara@core3.amsl.com
Delivered-To: shara@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 5EB7B3A6AAB for <shara@core3.amsl.com>; Thu, 12 Mar 2009 10:34:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.329
X-Spam-Level:
X-Spam-Status: No, score=-6.329 tagged_above=-999 required=5 tests=[AWL=0.270, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N0vL2T6M70X4 for <shara@core3.amsl.com>; Thu, 12 Mar 2009 10:34:10 -0700 (PDT)
Received: from sj-iport-2.cisco.com (sj-iport-2.cisco.com [171.71.176.71]) by core3.amsl.com (Postfix) with ESMTP id 72F3D3A680B for <shara@ietf.org>; Thu, 12 Mar 2009 10:34:10 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="4.38,351,1233532800"; d="scan'208";a="141005730"
Received: from sj-dkim-2.cisco.com ([171.71.179.186]) by sj-iport-2.cisco.com with ESMTP; 12 Mar 2009 17:34:48 +0000
Received: from sj-core-4.cisco.com (sj-core-4.cisco.com [171.68.223.138]) by sj-dkim-2.cisco.com (8.12.11/8.12.11) with ESMTP id n2CHYmUY029078; Thu, 12 Mar 2009 10:34:48 -0700
Received: from dwingwxp01 ([10.32.240.194]) by sj-core-4.cisco.com (8.13.8/8.13.8) with ESMTP id n2CHYlpG012053; Thu, 12 Mar 2009 17:34:47 GMT
From: "Dan Wing" <dwing@cisco.com>
To: "'Jan Zorz @ go6.si'" <jan@go6.si>, <shara@ietf.org>
References: <022a01c9a2ab$fd5abf60$fd736b80@cisco.com> <49B91C8B.5010906@go6.si>
Date: Thu, 12 Mar 2009 10:34:45 -0700
Message-ID: <04a201c9a338$d5ce8f70$fd736b80@cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 11
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3350
In-Reply-To: <49B91C8B.5010906@go6.si>
Thread-Index: AcmjL5Z3CZdN0U89Q/KOw2gwsGUEkwACHdpg
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; l=1042; t=1236879288; x=1237743288; c=relaxed/simple; s=sjdkim2002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=dwing@cisco.com; z=From:=20=22Dan=20Wing=22=20<dwing@cisco.com> |Subject:=20RE=3A=20[shara]=20port=20randomization=20(draft -ymbk-aplusp-03) |Sender:=20; bh=pLgSQMM/CTchVHvkT8uxCTC2Jh6ez6UdiqqTO8yKjcs=; b=GUN/W/xGegIh3Fy7L5Xb+X0ZEv2vSHxoc+TpgmpyVHn8AGQoFRJElwArAW mFdHVUvzBu0/U8jvPHR4UzWPgQKdCUbDmNWPxv36bXRDDBS/NweOaPM0JTlf /yyikzPEV3;
Authentication-Results: sj-dkim-2; header.From=dwing@cisco.com; dkim=pass ( sig from cisco.com/sjdkim2002 verified; );
Subject: Re: [shara] port randomization (draft-ymbk-aplusp-03)
X-BeenThere: shara@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Sharing of an IPv4 Address discussion list <shara.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/shara>, <mailto:shara-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/shara>
List-Post: <mailto:shara@ietf.org>
List-Help: <mailto:shara-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shara>, <mailto:shara-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Mar 2009 17:34:11 -0000

> How important is port randomization and how big is the impact in real 
> life,

Over the last 10 years there have been several attacks against
TCP and DNS that have exploited predictable emphemeral ports.  The
industry response to those attacks has been to (a) randomize 
ephemeral port selection (rather than incrementing to the next 
port number) and (b) increase the ephemeral port range used by 
the OS.

See
http://tools.ietf.org/html/draft-ietf-tsvwg-port-randomization-02#section-1
for more detailed answer to your question.

-d


> if we randomize within
> smaller range? Is it worthy to make already complex solution 
> (shared IP) 
> even more complex just because of that?
> 
> Regards, Jan Zorz
> > -d
> >
> >
> > _______________________________________________
> > shara mailing list
> > shara@ietf.org
> > https://www.ietf.org/mailman/listinfo/shara
> >   
> _______________________________________________
> shara mailing list
> shara@ietf.org
> https://www.ietf.org/mailman/listinfo/shara