[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [DNA] Review of draft-ietf-dna-link-information-03.txt



> Since it doesn't make sense to send out RS probes on a "Link Down" 
> indication, or as the result of events such as rate negotiation, I assume 
> that "changed" means "Link Up", no?
>
>>IHO, regardless of what the spec says about the host side, somebody could 
>>always hack the driver to flood the link. The DT was primarily concerned 
>>with protecting against such attacks, but I suppose it might be 
>>appropriate to include some text in the spec to protect against 
>>malfunctions as well.
>

Yes.

> The issue isn't so much DoS (since as you point out, attacks don't have to 
> implement the spec), as protecting against malfunctioning drivers.  For 
> example, I have seen drivers that don't damp "Link Up" and so it is 
> possible to receive ~10 indications per second in some circumstances.   If 
> a number of hosts all had the same problem (e.g. if such a malfunctioning 
> driver made its way into a mass-market handset), DNA implementations 
> without built-in damping could cause serious problems.
>

Certainly from the host side that is true.

            jak