4 ms·
Yes, you can for example require the first datagram in a connection to have a cryptographically signed blob of data (also useful for key exchange). But then you
by exDM69 3y ago
Yes, you can for example require the first datagram in a connection to have a cryptographically signed blob of data (also useful for key exchange). But then you need some mitigation against a simple replay attack (client sends same packet twice).
The server's first response should be much smaller in size than the client's request.
The basic idea is to make the client (attacker) use more bandwidth and CPU time than the server, at least during the connection handshake phase. This makes the server unappealing as a target for attack, even through it does not downright prevent the attack.
Most protocols already employ such schemes in connection handshake and crypto key exchange.