RE: Re: [tcpm] Revision of draft-larsen-tsvwg-port-randomization
2007-06-01 22:38:33 GMT
Lars Eggert [mailto:lars.eggert <at> nokia.com] wrote: > On 2007-2-11, at 17:56, ext Fernando Gont wrote: > > We have published a revision of the port randomization draft > > (draft-larsen-tsvwg-port-randomization). This version addresses > > feedback from Alfred Hoenes and Carlos Pignataro, and comments from > > FreeBSD's Mike Silbersack. The draft is targetted at tsvwg because > > the same stuff can be applied to other protocols. But most (all?) of > > the work on this has been done mainly for TCP. > > The update is at http://tools.ietf.org/html/draft-larsen-tsvwg-port- > randomization. > > The concepts in this draft are likely relevant to most of our > transport protocols, and hence would be in scope for TSVWG. > The TSVWG > chairs are interested in comments on whether there is group interest > in this draft - please comment on tsvwg <at> ietf.org. The suggestions in this document are equally important for RTP so that attackers are forced to work harder to inject undesired content into RTP media sessions. It would be useful if the document scope were expanded slightly to explicitly include RTP. For example, the Abstract currently says: Recently, awareness has been raised about a number of "blind" attacks that can be performed against the Transmission Control Protocol (TCP) and similar protocols. it is hard to say that RTP is similar to TCP. Thus, I would suggest changing it to something like this:(Continue reading)
RSS Feed