And if you knock blindly on a few doors, the system knows you’re an intruder, and no soup for you even if you stumble into the right knock sequence.
And if you knock blindly on a few doors, the system knows you’re an intruder, and no soup for you even if you stumble into the right knock sequence.
AKA port knocking[1], minus the special twist at the end where an intrusion/network detection system (IDS or NDS) automagically detects failed port knocks and responds accordingly.
Consider an 0day for example. When the 0day is published, attackers are going to mass-scan the internet for vulnerable applications. Your WAFs, etc won't yet block the attack, and if you have a vulnerable application that must be externally facing, you may get hit by this mass-scan. If your applications are protected with port knocking, however, you'll have that extra window of time to apply patches and protect yourself before you're directly targeted.
It might be a decent extra tool for very delicate situations, but I find it reasonably clear that it's largely self-defeating and not to be relied upon. It can also introduce further bugs.
I can see it could have an appeal as a proper password system though (not an obscurity device), since it's really the first step in interacting with a server. With password protocols, you usually have a more complicated interaction that can open a greater surface area. It seems good practice to authenticate absolutely as soon as possible.
Even if everybody were to use port knocking, knowing that fact doesn't give you any knowledge about whether a given IP hosts zero, one, or some arbitrary number of possibly vulnerable services.
A theme of the site is to push the idea generating code from models by using Model Compilers to continuously improve and optimise future Model Compilers as shown graphically in the Analysis Design Matrix Diagram.
Edit: Sorry I misread your comment as talking about replay attacks, not MITM'ing. I'm not an expert, but I believe MITM attacks are typically mitigated by performing the knock out of band over a covert channel (DNS, etc). AFAIK, there isn't really a way to prevent them entirely.
>to send specific packets in a specific sequence on specific ports.
like Gothic Motel model itself it looks like an unnecessary complication. I think we can get pretty much the same effect if typical password (its hash) was sent in a sequence of say 10 packets instead of 1.