IPsec Replay

preview_player
Показать описание
This tutorial explains how IPsec performs protection against replay attacks. The general idea of a replay attack has been explained by us in an earlier movie; this movie focuses on IPsec. It shows how IPsec uses sequence numbers and a window mechanism to detect such attacks. It also touches the difference between the IPsec window mechanism and that of TCP.
Рекомендации по теме
Комментарии
Автор

Thanks for sharing this video, it's very useful. But I have a question here: in your example of out of sequence packets, suppose packet 5 was intercepted by the attacker and was retransmitted to the destination before the real packet arrived at the destination. Maybe the receiver will receive the replayed packet 5 and it will pass the authentication first and mark the window that 5 is received. After that, if the real packet 5 arrives at the receiver, it will discard the packet. Will this happen?

yingwu