@techreport{song-ipsecme-seq-icv-01, number = {draft-song-ipsecme-seq-icv-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-song-ipsecme-seq-icv/01/}, author = {Jifei Song and Tina Tsou (Ting ZOU) and Vishwas Manral}, title = {{IPsec sequence number integrity check value}}, pagetotal = 10, year = 2013, month = jul, day = 8, abstract = {This document specifies an IPsec AH and ESP sequence number validation scheme, which is complementary to the existing ICV mechanism and anti-replay mechanism of AH and ESP in defense against DOS attack. It is an optional feature negotiable through IKE, for this feature to be negotiated, both sender and receiver must implement it. If any party doesn't support it, then this feature should be excluded from negotiation. The rationale for such a scheme is discussed first; then requirements and guidelines for design of the scheme are laid out. There can be various ways to implement the scheme, some reference designs are discussed to set the base for effort of identifying best practice and eventually establishing a standard on the subject.}, }