Martin Fowler's Gothic Hotel Model – How It Should Be Done
analysisdesignmatrix.com
analysisdesignmatrix.com
This has been around since at least the 90s, but back then it was called port knocking. I remember seeing an implementation in the 90s that required different ICMP echo packet sizes (say 56, 64, 64, then 56 bytes) sent in order for the system to unfirewall a particular service port for that incoming IP.
What if we don't use different ports? Your example uses ICMP packages with different sizes, not ports. What if you use something at the application layer that doesn't require ports, maybe a sequence of (invalid) calls to separate end-points?
Personally, I don't care how it's called as long as everyone agrees on what it is and here, again, I agree with you in that "Gothic Hotel" might not be the best name.
[0] Just the other day I heard a plain-old FTP server described as "cloud-based storage service".
And if you knock blindly on a few doors, the system knows you’re an intruder, and no soup for you even if you stumble into the right knock sequence.
AKA port knocking[1], minus the special twist at the end where an intrusion/network detection system (IDS or NDS) automagically detects failed port knocks and responds accordingly.
Consider an 0day for example. When the 0day is published, attackers are going to mass-scan the internet for vulnerable applications. Your WAFs, etc won't yet block the attack, and if you have a vulnerable application that must be externally facing, you may get hit by this mass-scan. If your applications are protected with port knocking, however, you'll have that extra window of time to apply patches and protect yourself before you're directly targeted.
It might be a decent extra tool for very delicate situations, but I find it reasonably clear that it's largely self-defeating and not to be relied upon. It can also introduce further bugs.
I can see it could have an appeal as a proper password system though (not an obscurity device), since it's really the first step in interacting with a server. With password protocols, you usually have a more complicated interaction that can open a greater surface area. It seems good practice to authenticate absolutely as soon as possible.
Even if everybody were to use port knocking, knowing that fact doesn't give you any knowledge about whether a given IP hosts zero, one, or some arbitrary number of possibly vulnerable services.
>to send specific packets in a specific sequence on specific ports.
like Gothic Motel model itself it looks like an unnecessary complication. I think we can get pretty much the same effect if typical password (its hash) was sent in a sequence of say 10 packets instead of 1.
A theme of the site is to push the idea generating code from models by using Model Compilers to continuously improve and optimise future Model Compilers as shown graphically in the Analysis Design Matrix Diagram.
Edit: Sorry I misread your comment as talking about replay attacks, not MITM'ing. I'm not an expert, but I believe MITM attacks are typically mitigated by performing the knock out of band over a covert channel (DNS, etc). AFAIK, there isn't really a way to prevent them entirely.