Re: Summary of responses so far and proposal moving forward[WasRe: [tcpm] Is this a problem?]

Ethan Blanton <eblanton@cs.ohiou.edu> Tue, 27 November 2007 23:37 UTC

Return-path: <tcpm-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ix9zs-00069I-Ig; Tue, 27 Nov 2007 18:37:44 -0500
Received: from tcpm by megatron.ietf.org with local (Exim 4.43) id 1Ix9zr-00068z-40 for tcpm-confirm+ok@megatron.ietf.org; Tue, 27 Nov 2007 18:37:43 -0500
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Ix9zq-00068k-PC for tcpm@ietf.org; Tue, 27 Nov 2007 18:37:42 -0500
Received: from psg.com ([147.28.0.62]) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1Ix9zq-0004AY-Ce for tcpm@ietf.org; Tue, 27 Nov 2007 18:37:42 -0500
Received: from [67.59.55.189] (helo=elb.elitists.net) by psg.com with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.68 (FreeBSD)) (envelope-from <eblanton@cs.ohiou.edu>) id 1Ix9zk-0002va-DA for tcpm@ietf.org; Tue, 27 Nov 2007 23:37:42 +0000
Received: from colt.internal (colt [192.168.33.1]) by elb.elitists.net (Postfix) with ESMTP id DB56D2BE21 for <tcpm@ietf.org>; Tue, 27 Nov 2007 18:37:33 -0500 (EST)
Received: by colt.internal (Postfix, from userid 3000) id 26C362842B; Tue, 27 Nov 2007 18:37:33 -0500 (EST)
Date: Tue, 27 Nov 2007 18:37:33 -0500
From: Ethan Blanton <eblanton@cs.ohiou.edu>
To: tcpm@ietf.org
Subject: Re: Summary of responses so far and proposal moving forward[WasRe: [tcpm] Is this a problem?]
Message-ID: <20071127233733.GB20243@elb.elitists.net>
Mail-Followup-To: tcpm@ietf.org
References: <20071126161259.29EFA2FC343@lawyers.icir.org> <474AF34B.40805@isi.edu> <474B3C35.30207@cisco.com> <474B935E.4040207@isi.edu> <474C92A5.7070208@cisco.com>
MIME-Version: 1.0
In-Reply-To: <474C92A5.7070208@cisco.com>
X-GnuPG-Fingerprint: A290 14A8 C682 5C88 AE51 4787 AFD9 00F4 883C 1C14
User-Agent: Mutt/1.5.13 (2006-08-11)
X-Spam-Score: -103.1 (---------------------------------------------------)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 5a9a1bd6c2d06a21d748b7d0070ddcb8
X-BeenThere: tcpm@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tcpm@ietf.org>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============0745033313=="
Errors-To: tcpm-bounces@ietf.org

Mahesh Jethanandani spake unto us the following wisdom:
> Joe Touch wrote:
> >Mahesh Jethanandani wrote:
> >>Joe Touch wrote:
> >>>Note also that DOS attacks would likely not keep TCP connections around
> >>>with zero windows AND continue to ACK - they'd stop ACKing, the
> >>>connection would drop for *that* reason, and be recovered.
> >>
> >>Quite the contrary. Our experimentation revealed that DoS attackers
> >>responded reliably with an ACK to all zero window probes and that
> >>connections stayed in established state for days.
> >
> >OK - so how do you know these were attacks? Or are you calling any
> >consumption of resources you don't expect an attack
>
> They were attacks because we had initiated them as such.

This is _very different_ from what you claimed before.  You are
claiming that attacks *do exist* which reliably ACK zero window probes
-- but you don't know that, and have no support for it.  You have
support for the fact that an attack *can be created* which ACKs zero
window probes.

Joe's point, and I think it is valid, is that this is an attack which
requires a commitment of resources on the part of the attacker.

That said, I agree that such an attack *could* be created, though it
appears that no one has.

Ethan

-- 
The laws that forbid the carrying of arms are laws [that have no remedy
for evils].  They disarm only those who are neither inclined nor
determined to commit crimes.
		-- Cesare Beccaria, "On Crimes and Punishments", 1764
_______________________________________________
tcpm mailing list
tcpm@ietf.org
https://www1.ietf.org/mailman/listinfo/tcpm