summaryrefslogtreecommitdiff
path: root/internet-draft-satp.xml
diff options
context:
space:
mode:
authorOthmar Gsenger <otti@anytun.org>2007-04-27 18:32:09 +0000
committerOthmar Gsenger <otti@anytun.org>2007-04-27 18:32:09 +0000
commitb0683b2447e6041488ae9e7d4db065276d4531fc (patch)
tree16e8c1dc34f9899d883a6de463a707e11b9574cd /internet-draft-satp.xml
parenti (diff)
i
Diffstat (limited to 'internet-draft-satp.xml')
-rw-r--r--internet-draft-satp.xml2
1 files changed, 1 insertions, 1 deletions
diff --git a/internet-draft-satp.xml b/internet-draft-satp.xml
index 01f717c..7dca65d 100644
--- a/internet-draft-satp.xml
+++ b/internet-draft-satp.xml
@@ -270,7 +270,7 @@ HEX
<section title="Security Considerations">
<t>As SATP uses the same encrytion technics as <xref target="RFC3711">SRTP</xref>, it shares the same security issues. This section will only discuss some small changes. Please read <xref target="RFC3711">SRTP RFC3711 section 9</xref> for details.</t>
<section title="Replay protection">
- <t>Replay protection is done by a replay list. Every anycast receiver has it's own replay list, which SOULDN'T be syncronised, because of massive overhead. This leads to an additional possible attack. A attacker is able to replay a captured packet once to every anycast reciever. This attack is considered of be very unlikely, because multiple attack hosts in different loactions are needed to reach the seperate anycast receivers and the number of replays is limited to the count of receivers - 1. Such replays might also happen because of routing problems, so a payload protocol HAS TO be robust against a small number of duplicated packages. The window size and position HAS TO be syncronised between multible anycast receivers to limit this attack.</t>
+ <t>Replay protection is done by a replay list. Every anycast receiver has it's own replay list, which SHOULDN'T be syncronised, because of massive overhead. This leads to an additional possible attack. A attacker is able to replay a captured packet once to every anycast reciever. This attack is considered of be very unlikely, because multiple attack hosts in different loactions are needed to reach the seperate anycast receivers and the number of replays is limited to the count of receivers - 1. Such replays might also happen because of routing problems, so a payload protocol HAS TO be robust against a small number of duplicated packages. The window size and position HAS TO be syncronised between multible anycast receivers to limit this attack.</t>
</section>
</section>
<section title="IANA Considerations">