republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Huge Internet Security Hole Demonstrated » Old news?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
The DNS exploit is bigger... »
« So encrypt your traffic  
AuthorAll Replies


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

reply to wentlanc
Re: Old news?

said by wentlanc See Profile :

Perhaps monitoring routing tables for AS path changes would be key to picking up this kind of exploit?

cw
That can be done, but it is labor intensive and even then likely to not work:
A handful of academic groups collect BGP routing information from cooperating ASes to monitor BGP updates that change traffic's path. But without context, it can be difficult to distinguish a legitimate change from a malicious hijacking. There are reasons traffic that ordinarily travels one path could suddenly switch to another -- say, if companies with separate ASes merged, or if a natural disaster put one network out of commission and another AS adopted its traffic. On good days, routing paths can remain fairly static. But "when the internet has a bad hair day," Kent said, "the rate of (BGP path) updates goes up by a factor of 200 to 400."

Kapela said eavesdropping could be thwarted if ISPs aggressively filtered to allow only authorized peers to draw traffic from their routers, and only for specific IP prefixes. But filtering is labor intensive, and if just one ISP declines to participate, it "breaks it for the rest of us," he said.

"Providers can prevent our attack absolutely 100 percent," Kapela said. "They simply don't because it takes work, and to do sufficient filtering to prevent these kinds of attacks on a global scale is cost prohibitive."

--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?
-
Forums » Huge Internet Security Hole DemonstratedThe DNS exploit is bigger... »
« So encrypt your traffic  


Tuesday, 01-Dec 11:27:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [62] Baltimore To Ban Lazy Cable Installs
· [53] Broadband Killed The Game Console
· [38] Rural Carriers Quickly Embracing Fiber
· [36] Rogers Unveils The ISP Dream Model
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [30] Charter Exits Chapter 11
· [24] Midcontinent Socked With Easement Lawsuit
· [12] ACTA: Global Three Strikes
· [12] Vivendi Agrees, Comcast/NBC Deal Soon
· [4] Monday Evening Links
Most people now reading
· [Rant] called out sick! [Rants, Raves, and Praise]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· buying a one way ticket [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [OOL] Youtube not loading [OptimumOnline]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Leveling to 85 [World of Warcraft]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]