Too big or too small? The PTB-PTS ICMP-based attack against IPsec gateways

Global Communications Conference(2014)

引用 4|浏览10
暂无评分
摘要
This work introduces the "Packet Too Big"-"Packet Too Small" ICMP based attack against IPsec gateways. We explain how an attacker having eavesdropping and packet injection capabilities, from the insecure network where he only sees encrypted packets, can force a gateway to reduce the Path MTU of an IPsec tunnel to the minimum, which triggers severe issues for the hosts behind this gateway: depending on the Path MTU discovery algorithm in use, the attack either creates a Denial of Service or major performance penalties. This attack highlights two fundamental problems that we discuss, along with potential counter-measures to mitigate the attack while keeping ICMP benefits.
更多
查看译文
关键词
IP networks,computer network security,IPsec gateways,PTB-PTS ICMP-based attack,denial of service,internet control message protocol,packet too big,packet too small,path MTU discovery algorithm,path maximum transmission unit discovery
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要