stoffi92 / rfc5575bis

0 stars 0 forks source link

IESG Benjamin Kaduk: malicious neighbor draw traffic #211

Closed stoffi92 closed 4 years ago

stoffi92 commented 4 years ago

Inter-provider routing is based on a web of trust. Neighboring autonomous systems are trusted to advertise valid reachability information. If this trust model is violated, a neighboring autonomous system may cause a denial-of-service attack by advertising reachability information for a given prefix for which it does not

I guess it's also a well-known attack that malicious neighbor could also draw traffic to itself for snooping purposes without actually dropping the traffic. But I'm not sure if there are any flowspec-specific considerations relating to that scenario.

suehares commented 4 years ago

It is a well know attack that honey pots can draw traffic for snooping. Not the problem for this specification.