Re: [tcpm] DoS attack from misbehaving receivers
Joe Touch <touch@ISI.EDU> Thu, 11 January 2007 22:12 UTC
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1H589p-0000KE-Bw; Thu, 11 Jan 2007 17:12:25 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1H589o-0000Is-06 for tcpm@ietf.org; Thu, 11 Jan 2007 17:12:24 -0500
Received: from vapor.isi.edu ([128.9.64.64]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1H589m-0003l4-KY for tcpm@ietf.org; Thu, 11 Jan 2007 17:12:23 -0500
Received: from [127.0.0.1] ([128.9.176.75]) by vapor.isi.edu (8.13.8/8.13.8) with ESMTP id l0BMC7SW002881; Thu, 11 Jan 2007 14:12:10 -0800 (PST)
Message-ID: <45A6B635.30801@isi.edu>
Date: Thu, 11 Jan 2007 14:12:05 -0800
From: Joe Touch <touch@ISI.EDU>
User-Agent: Thunderbird 1.5.0.9 (Windows/20061207)
MIME-Version: 1.0
To: Caitlin Bestler <caitlinb@broadcom.com>
Subject: Re: [tcpm] DoS attack from misbehaving receivers
References: <54AD0F12E08D1541B826BE97C98F99F1EE6E61@NT-SJCA-0751.brcm.ad.broadcom.com>
In-Reply-To: <54AD0F12E08D1541B826BE97C98F99F1EE6E61@NT-SJCA-0751.brcm.ad.broadcom.com>
X-Enigmail-Version: 0.94.0.0
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 92df29fa99cf13e554b84c8374345c17
Cc: david.malone@nuim.ie, tcpm@ietf.org
X-BeenThere: tcpm@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tcpm@ietf.org>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============2108641758=="
Errors-To: tcpm-bounces@ietf.org
Caitlin Bestler wrote: ... >>> Having the sender skip segments will indeed detect a non-compliant >>> receiver that acks segments that were never sent. But sending >>> non-contiguous TCP segments is itself not compliant. >> Technically, that's equivalent to losing or reordering >> segments. As long as you can't tell the difference from the >> receiver's point of view, why is this not compliant? >> >> Joe > > There's a difference between L3 or L2 dropping a segment > because a queue was full and L4 simply not generating it. Not to the receiver! ('goes to intent' - the receiver doesn't know intent). > Granted, there is no method to prove the difference when > observing from the other end of the network, but that still > isn't a reason to bless generation of non-compliant TCP streams. It's not non-compliant to do something that the receiver can't differentiate from legitimate behavior. > A TCP connection is supposed to be a peer-to-peer relationship. > Once you start playing liar's poker to try to trip up the other > end things are going to get messy very quickly. What if receivers > started doing things to try to detect sender's who were sending > out of order? What would you do? You can't punish them, since you can't know whether the network is the cause or not. The better quote might be a version of the (in)famous "don't attribute to malice that which can be attributed to ignorance"; my version here would be: "don't attribute to malice that which can be attributed to entropy" Joe -- ---------------------------------------- Joe Touch Sr. Network Engineer, USAF TSAT Space Segment
_______________________________________________ tcpm mailing list tcpm@ietf.org https://www1.ietf.org/mailman/listinfo/tcpm
- [tcpm] DoS attack from misbehaving receivers Stephen Hemminger
- Re: [tcpm] DoS attack from misbehaving receivers Joe Touch
- RE: [tcpm] DoS attack from misbehaving receivers Caitlin Bestler
- RE: [tcpm] DoS attack from misbehaving receivers Caitlin Bestler
- Re: [tcpm] DoS attack from misbehaving receivers Rob Sherwood
- Re: [tcpm] DoS attack from misbehaving receivers Joe Touch
- RE: [tcpm] DoS attack from misbehaving receivers Caitlin Bestler
- RE: [tcpm] DoS attack from misbehaving receivers Christian Huitema
- Re: [tcpm] DoS attack from misbehaving receivers Joe Touch
- Re: [tcpm] DoS attack from misbehaving receivers John Heffner
- Re: [tcpm] DoS attack from misbehaving receivers Rob Sherwood
- Re: [tcpm] DoS attack from misbehaving receivers Gavin McCullagh
- RE: [tcpm] DoS attack from misbehaving receivers Caitlin Bestler
- Re: [tcpm] DoS attack from misbehaving receivers David Malone
- Re: [tcpm] DoS attack from misbehaving receivers Gavin McCullagh
- Re: [tcpm] DoS attack from misbehaving receivers Rob Sherwood
- Re: [tcpm] DoS attack from misbehaving receivers Mark Allman
- Re: [tcpm] DoS attack from misbehaving receivers Rob Sherwood
- Re: [tcpm] DoS attack from misbehaving receivers Mark Allman
- Re: [tcpm] DoS attack from misbehaving receivers Rob Sherwood
- Re: [tcpm] DoS attack from misbehaving receivers Mark Allman