首页> 外文会议>IEEE Global Communications Conference >Too big or too small? The PTB-PTS ICMP-based attack against IPsec gateways
【24h】

Too big or too small? The PTB-PTS ICMP-based attack against IPsec gateways

机译:太大还是太小?基于PTB-PTS ICMP的IPsec网关攻击

获取原文

摘要

This work introduces the "Packet Too Big"-"Packet Too Small" ICMP based attack against IPsec gateways. We explain how an attacker having eavesdropping and packet injection capabilities, from the insecure network where he only sees encrypted packets, can force a gateway to reduce the Path MTU of an IPsec tunnel to the minimum, which triggers severe issues for the hosts behind this gateway: depending on the Path MTU discovery algorithm in use, the attack either creates a Denial of Service or major performance penalties. This attack highlights two fundamental problems that we discuss, along with potential counter-measures to mitigate the attack while keeping ICMP benefits.
机译:这项工作介绍了针对IPsec网关的基于“ ICMP攻击”的“ Packet Too Big”-“ Packet Too Small”。我们说明了攻击者如何从不安全的网络(仅看到加密的数据包)具有窃听和数据包注入功能,如何迫使网关将IPsec隧道的Path MTU减小到最小,从而触发该网关后面的主机的严重问题:根据使用的路径MTU发现算法,攻击可能会造成拒绝服务或严重的性能损失。这次攻击突出了我们讨论的两个基本问题,以及在保持ICMP利益的同时减轻攻击的潜在对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号