mobike-3----Page:7
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18  19  20 

3rd Party Bombing
How much protection we offer against 3rd party bombing
almost none, [A-B] (IKEv2 NAT-T)
limited, [A-B and (B-C or A)] (return routability without cookies)
partial [A-B and B-C] (return routability with cookies)
Full [A inside path B-C] (authenticate outer IP-addresses, incompatible with NATs)
Terms
A, B = MOBIKE hosts, C = host attacked
A-B = along path between A and B
B-C = along path between B and C
Do we care if A is the attacker
PPT Version