A Simplified Solution For Critical A-MPDU DoS Issues

Slides:



Advertisements
Similar presentations
Doc.: IEEE /0703r0 Submission March 2008 Luke Qian etc, Cisco Systems, IncSlide 1 Issues and Solutions to IEEE n A-MPDU Denial of Service.
Advertisements

Doc.: IEEE /0755r1 Submission March 2008 Luke Qian etc, Cisco Systems, IncSlide 1 Review of n A-MPDU DoS Issues – Progress and Status Authors:
Doc.: IEEE /1021r1 Submission September 2008 Luke Qian etc.Slide 1 A Simplified Solution For Critical A-MPDU DoS Issues Date: Authors:
Doc.: IEEE /0562r0 Submission May 2008 Adrian Stephens, Intel CorporationSlide 1 TGn LB124 – A detect and mitigate solution to the BA DoS problems.
Doc.: IEEE /0833r2 Submission July 2008 Luke Qian etc, CiscoSlide 1 A Proposed Scaled-down Solution to A- MPDU DoS Related Comments in LB 129.
Doc.: IEEE /1021r3 Submission September 2008 Luke Qian etc.Slide 1 A Simplified Solution For Critical A-MPDU DoS Issues Date: Authors:
Doc.: IEEE /0833r3 Submission July 2008 Luke Qian etc, CiscoSlide 1 A Proposed Scaled-down Solution to A- MPDU DoS Related Comments in LB 129.
Doc.: IEEE /0018r0 Submission January 2010 Alexander Tolpin, Intel CorporationSlide 1 4 –Way Handshake Synchronization Issue Date:
Doc.: IEEE /0094r2 Submission Jan 2012 Slide 1 Authors: MAC Header Design for Small Data Packet for ah Date: Lv kaiying, ZTE.
Doc.: IEEE /0840r1 Submission AP Assisted Medium Synchronization Date: Authors: September 2012 Minyoung Park, Intel Corp.Slide 1.
Doc.: IEEE /0150r0 Submission May 2013 Osama Aboul-Magd (Huawei Technologies)Slide 1 GCR using SYNRA for GLK Date: Authors:
Doc.: IEEE /0079r0 Submission Interference Signalling Enhancements Date: xx Mar 2010 Allan Thomson, Cisco SystemsSlide 1 Authors:
Doc.: IEEE /0485r0 Submission May 2004 Jesse Walker and Emily Qi, Intel CorporationSlide 1 Management Protection Jesse Walker and Emily Qi Intel.
Doc.:IEEE /0313r1 Submission Robert Stacey (Intel) March 12, 2010 Slide 1 Rekeying Protocol Fix Authors: Date:
Doc.: IEEE /250r0 Submission, Slide 1 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: IEEE :
Doc.: IEEE /0150r11 Submission July 2015 Ganesh Venkatesan (Intel Corporation)Slide 1 GCR using SYNRA for GLK Date: Authors:
Doc.: IEEE /0615r0 Submission May 2008 Naveen K. Kakani, Nokia IncSlide 1 Multicast Transmission in WLAN Date: Authors:
Submission doc.: IEEE /0961r0 July 2016 Hanseul Hong, Yonsei UniversitySlide 1 Consideration on Multi-STA BlockAck Optimization Date:
Location Measurement Protocol for Unassociated STAs
Protected LTF Using PMF in SU and MU Modes
Broadcast and Unicast Management Protection (BUMP)
TSN Architecture Mike Moreton, STMicroelectronics
Requirements and Implementations for Intra-flow/Intra-AC DiffServ
Requirements and Implementations for Intra-flow/Intra-AC DiffServ
GAPA - Efficient, More Reliable Multicast
May 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Considerations on general MAC frame] Date Submitted:
Block Ack Security Authors: May 2008 Date: May 2008
Multicast/Broadcast Communication With Acknowledge
120MHz channelization solution
Broadcast and Unicast Management Protection (BUMP)
Regarding UL MU protection
Traffic Class Control in MBSS
Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Improved Delayed ACK response Frame for.
July 2002 Threat Model Tim Moore Tim Moore, Microsoft.
Traffic Class Control in MBSS
Beacon Protection Date: Authors: July 2018 July 2018
Beacon Protection Date: Authors: May 2018 January 2018
GAPA - Efficient, More Reliable Multicast
Regarding HE fragmentation
July 2008 doc.: IEEE /0833r0 July 2008 A Proposed Scale-down Solution to A-MPDU DoS Related Comments in LB 129 Date: Authors: Luke.
DL MU-MIMO ack protocol
A Simplified Solution For Critical A-MPDU DoS Issues
Reducing Overhead in Active Scanning with Simulation Results
Objectives of Explicit Feedback rules
CID#89-Directed Multicast Service (DMS)
Block Ack Security Date: Authors: May 2008 May 2008
Rekeying Protocol Fix Date: Authors: Month Year
Group Block Acknowledgements for Multicast Traffic
Explicit Block Ack Request in DL MU PPDU
Reducing Overhead in Active Scanning with Simulation Results
A-MSDU Protection March 2007 Date: September 2006
Requirements and Implementations for Intra-flow/Intra-AC DiffServ
Traffic Class Control in MBSS
Beacon Protection Date: Authors: July 2018 July 2018
Aggregate Block-ACK definition
WUR Security Proposal Date: Authors: September 2017
WUR Security Proposal Date: Authors: September 2017
Interference Signalling Enhancements
A-MSDU Protection March 2007 Date: September 2006
Authenticated Validity for M2M devices
A-MSDU Protection March 2007 Date: September 2006
Requirements and Implementations for Intra-flow/Intra-AC DiffServ
More Reliable GroupCast Proposal Presentation
GCR using SYNRA for GLK Date: Authors: July 2015 Month Year
Power Efficiency for Individually Addressed Frames Reception
Review of n A-MPDU DoS Issues – Progress and Status
Unsolicited Block ACK Extension
Traffic Filter based Wakeup Service
July 2008 doc.: IEEE /0833r0 July 2008 A Proposed Scale-down Solution to A-MPDU DoS Related Comments in LB 129 Date: Authors: Luke.
Discussion on Multi-link Acknowledgement
Presentation transcript:

A Simplified Solution For Critical A-MPDU DoS Issues July 2008 doc.: IEEE 802.11-08/1021r0 September 2008 A Simplified Solution For Critical A-MPDU DoS Issues Date: 2008-09-04 Authors: Luke Qian etc. Luke Qian etc, Cisco

July 2008 doc.: IEEE 802.11-08/1021r0 September 2008 Abstract Current operation rules for A-MPDU and BAR facilitate a number of Denial of Service (DoS) attacks as presented in 802.11-08/0703r0. This submission proposes a simplified solution to mitigate the most damaging and easiest-to-launch ones. Luke Qian etc. Luke Qian etc, Cisco

Overview for the Issues September 2008 Overview for the Issues Per current 11n A-MPDU/BA rules, advanced SN in data frames or BAR can advance the left edge of the BA re-ordering buffer on the receiver. However, BAR is a control frame which is not encrypted, nor has any authentication information SN in a data frame is not protected with encryption. As a result, a receiver running BA can be exposed to DoS attacks by rogue devices which move the receiver BA reordering buffer with falsely advanced SN, potentially causing subsequent valid frames to be discarded Such identified DoS attacks include: (Ref. 11-08/0703) Forged packets with advanced Sequence Numbers (SN) Captured and Replayed packets with modified SN. Captured and Replayed packets with advanced SN without modification. False Block ACK Request (BAR) with advanced SN. False BA to prevent retransmission. They can cause severe performance degradation, such as drop of voice calls, lost connection for TCP traffic etc. Luke Qian etc.

Uniqueness of the DoS Issues July 2008 doc.: IEEE 802.11-08/1021r0 September 2008 Uniqueness of the DoS Issues Hit-and-run type of attack as only one packet is needed to cause the DoS. So an attacker does not need to be at the spot to launch attacks persistently, making it hard to identify or catch the attackers. Significantly long period of DoS for a single attack At the order of tens of seconds. Can cause disassociations or dropped sessions, especially problematic for tcp sessions and voice connections A regular DoS, CTS with excessive NAV setting for example, can only cause a DoS for a period of tens of ms, several order of magnitudes less than that of an A-MPDU DoS, and will have to repeatedly launch the attacks. Luke Qian etc. Luke Qian etc, Cisco

September 2008 The Proposed Approach Focus on the two easiest-to-launch DoS for a better acceptance in TGn: a) Forged packets with advanced Sequence Numbers (SN) . b) False Block ACK Request (BAR) with advanced SN. Note – they are the “fire and forget” attacks whereby an attacker need nothing but a single packet to launch a DoS. Luke Qian etc.

A Simpler Solution September 2008 July 2008 doc.: IEEE 802.11-08/1021r0 September 2008 A Simpler Solution Introduce a capability bit to signal the protection for backward compatibility Transmitter rules: Never sends BAR or data with a SN which would cause the receiver to advance the left edge over a “hole” Sends an 11w type of encrypted management action frame, the protected ADDBA, to advance the left edge of the receiver window over a “hole” when needed. Overload the existing ADDBA request frame ADDBA request already contains all the required information Just need to allow an ADDBA request to be used during an established BA session to move the left edge of receiver window Receiver rules: On receiving a BAR or data frame which advances the left edge of receiver window over a “hole”, drop the BAR and flag a DoS attack (immediate detection of attack upon receipt of just one frame from attacker), and tear down BA session to minimize disruption On receiving a protected ADDBA for an established BA session, adjust the left edge as requested. Add a footnote in the 11n spec to allow an alternative ordering of BA Reordering after MPDU decryption on the receiver. But preserve existing ordering option as well for backward compatibility. Luke Qian etc. Luke Qian etc, Cisco

A Capability Bit for Negotiation: RSN Element changes September 2008 A Capability Bit for Negotiation: RSN Element changes Pre-Auth No Pairwise PTKSA Replay Counter GTKSA Replay Counter Reserved PeerKey Enabled Reserved PBAC Resv B0 B1 B2 B3 B4 B5 B6 B8 B9 B10 B11 B12 B13 B15 Modified RSN Capabilities subfield of the RSN Element A bit for signaling the capability: PBAC – Protected BAR Capable Indicates capability to perform modified BAR rules and decryption ordering If both STA advertise PBAC=1, then PBAC SHALL be used If at least one STA of a pair advertises PBAC=0, then PBA SHALL NOT be used STA that supports PBAC must also indicate TGw (e.g. dot11RSNAProtectedManagementFramesEnabled) Luke Qian etc.

Specification change for order of operations September 2008 Specification change for order of operations Allow alternative ordering of Block Ack Reordering AFTER A-MPDU decryption step, but preserve existing ordering option as well for legacy implementations. Move MPDU Decryption and Integrity Function to here Luke Qian etc.