3 ms·
Please don't use or implement this "work in progress", it is terrible. For starters, the fundamental idea is backwards. People don't evade port enumeration to
by bcoates 12y ago
Please don't use or implement this "work in progress", it is terrible.
For starters, the fundamental idea is backwards. People don't evade port enumeration to hide from attackers, they evade it to hide from auditors. Thinking that makes you safer is equivalent to assuming the world goes away when you close your eyes. The defenders need to find every hole, the attackers need to find one. If you want a secure (and functional!) network, you want to make network service discovery easier, not harder.
They even admit it themselves:
Thus, it is increasingly important to minimize the visible footprint
of services on Internet hosts, thereby reducing the attack surface.
They think reducing the visible footprint results in a reduction of the attack surface, that is, they think concealment is cover.
Secondly, the non-technical portions are extremely misleading, for example:
[A]dversaries may be able to observe all traffic of an Internet host
and perform man-in-the-middle attacks on traffic originating from
specific clients.
This is a quote from a proposal that does not work at all to conceal traffic from passive listeners, let alone man-in-the middle attackers. You still know exactly what services are running if you can listen in, you don't need to port scan! Furthermore, if you can see selective response to a sufficient (smallish) number of these ISN tokens, you can start trying to guess the secret. No advice on appropriate shared secret selection or necessary secret length to mitigate this is given -- they claim the secret is 1024 bits, but give a test vector much shorter than that.
PS: I'm pretty sure this breaks if you use DNAT