Sunday, August 3, 2014

MPTCP - New concern for security folks? ;



I guess the security tools have a lot to catch up


(From the article)

If any of your security decisions, tools, thought-processes, manual processes, if they rely on any of... these four things, then something in those is going to break," he says. 
  1. If you expect to see all app layer data within a TCP stream; 
  2. if you expect to differentiate clients from servers based on the connection direction; 
  3. if you expect to tamper with or close bad connections midstream; 
  4. if attempt to associate logical connections to IP addresses. 

If you make any security decisions based on any of those, then those security mechanisms are going to break in the face of MPTCP.

The link below has more information:-

No comments:

Post a Comment