Re: snmpconf Comments on BCP-09

Hi -

Date: Thu, 01 Aug 2002 16:11:37 -0400
> A further liability of authentication traps can be seen when they
> are being generated in the face of a Denial Of Service (DOS) attack, in the
> form of a flood of PDUs with invalid community strings, on the
> agent system.  If it is bad enough that the system is having to
> respond to and recover from the invalid agent data accesses, but the
> problem will be compounded if a separate Autentication notification
> PDU is sent to each recipient on the management network.

It's not just authentication failure notifications that warrant
caution.  See point (4) in the security considerations section of
draft-ietf-adslmib-adslext-10.txt which describes this fun case:

|    4) ADSL layer connectivity from the ATU-R will permit the subscriber
|    to manipulate both the ADSL link directly and the ADSL overhead
|    control channel(AOC)/embedded operations channel (EOC)
|    for their own loop.  For example,  unchecked or unfiltered
|    fluctuations initiated by the subscriber could generate sufficient
|    notifications to potentially overwhelm either the management
|    interface to the network or the element manager.  Other attacks
|    affecting the ATU-R portions of the MIB may also be possible.

