[e2e] Can feedback be generated more fast in ECN?
Baoqing Ye
baoqing at Basit.COM
Wed Feb 21 18:09:40 PST 2001
> There are lots of reasons to stop senders when things have gone horribly
> wrong. DOS attacks are one of them, telling the sender to stop quickly and
> reminding them whenever they try to crank up again is good for the entire
> network, is it not? Don't you think people would like this feature if it
> helps to seriously constrain DOS attacks?
SQ or ECN can do little to stop DoS attacks. Here is why :
1) DoS apckets are mostly with spoofed-IP addresses, they won't respond to
any of the signals.
2) ECN (so does SQ) indeed helps the attackers, when legitimate users
respond but malicious ones don't ..as simple as that.
-Baoqing Ye-
Network Security, Verizon
More information about the end2end-interest
mailing list