[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

multi-addressing review (was:RE: New multiaddressing review and new MAST draft)



Hi Dave,

I think it is valuable to have a document covering the issues related to
multi-addressing, so thanks for doing it.

My main comment about the document is that the security section seems
incomplete to me.

The only considered threat is connection hijacking. I guess there much other
issues to consider.

IMHO the security section is focused on the threats reffered to the parties
involved in the communication. However, it is also important to consider the
new threats that the adoption of multi-addressing mechanisms means for other
hosts in the internet (for instance non-mobile, non multi-homed hosts)
For instance, flooding attacks, dos attacks.

Other type of attacks should also be considered such as time shifting
attacks.

I would recomend considering the analysis contained in
draft-nikander-mobileip-v6-ro-sec as an input. It contain a detailed
analysis of different attacks related to mobility.

Regards, marcelo

> -----Mensaje original-----
> De: owner-multi6@ops.ietf.org [mailto:owner-multi6@ops.ietf.org]En
> nombre de Dave Crocker
> Enviado el: miercoles, 17 de septiembre de 2003 2:36
> Para: multi6@ops.ietf.org
> Asunto: New multiaddressing review and new MAST draft
>
>
> Howdy.
>
> I've just submitted some new mobility/multihoming I-Ds for
> distribution. Meanwhile, they are available from my website, in
> text and MS
> Word formats.
>
> The first breaks out the "discussion" section of the original
> MAST paper and
> expands on it:
>
>      Choices for Support of Multiaddressing
>
>      Text:
>
> <http://brandenburg.com/specifications/draft-crocker-mast-analysis-00.txt>
>      MSWord :
>
> <http://brandenburg.com/specifications/draft-crocker-mast-analysis-00.doc>
>
>
> The second is the revised draft proposal:
>
>      Multiple Address Service For Transport (MAST):
>      An Extended Proposal
>
>      Text:
>
> <http://brandenburg.com/specifications/draft-crocker-mast-proposal-01.txt>
>      MSWord:
>
> <http://brandenburg.com/specifications/draft-crocker-mast-proposal-01.doc>
>
> d/
> -----
>  Dave Crocker <mailto:dcrocker@brandenburg.com>
>  Brandenburg InternetWorking <http://www.brandenburg.com>
>  Sunnyvale, CA USA <tel: +1.408.246.8253>; <fax: +1.408.850.1850>
>
>