The Defect of DTLS toward Detected Aged Packets
Wei Jun Yang, Jiang Du · 2018
DTLS (Datagram Transport Layer Security) is aimed at providing secure encryption and authentication services for UDP. Compared to TLS (for TCP), DTLS made changes in several areas due to the unreliability of UDP. But it has no clear strategy in response to certain extreme situation such as a replay detect loop which could lead to the potential malicious threat like DDoS. This paper will mainly analyse the defect of DTLS specifications regarding the way to handle a detected replayed message. In addition, several attack experiments will be given to help reveal the defect and the brief descriptions of corresponding solutions will be introduced.