
From nobody Sun Oct  4 08:37:38 2015
Return-Path: <Stefan.Fouant@corero.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1DD461B29C2 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 08:37:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.599
X-Spam-Level: *
X-Spam-Status: No, score=1.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CHARSET_FARAWAY_HEADER=3.2, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5L6pSweTougm for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 08:37:36 -0700 (PDT)
Received: from mail1.bemta12.messagelabs.com (mail1.bemta12.messagelabs.com [216.82.251.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 063F91B29C1 for <dots@ietf.org>; Sun,  4 Oct 2015 08:37:35 -0700 (PDT)
Received: from [216.82.250.19] by server-3.bemta-12.messagelabs.com id D1/27-27945-FB741165; Sun, 04 Oct 2015 15:37:35 +0000
X-Env-Sender: Stefan.Fouant@corero.com
X-Msg-Ref: server-10.tower-87.messagelabs.com!1443973051!32358515!1
X-Originating-IP: [71.184.227.49]
X-StarScan-Received: 
X-StarScan-Version: 6.13.16; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 31852 invoked from network); 4 Oct 2015 15:37:32 -0000
Received: from mercury.corero.com (HELO MERCURY.corero.com) (71.184.227.49) by server-10.tower-87.messagelabs.com with AES128-SHA encrypted SMTP; 4 Oct 2015 15:37:32 -0000
Received: from MERCURY.corero.com ([fe80::2c05:6b26:abe2:ad24]) by MERCURY.corero.com ([fe80::2c05:6b26:abe2:ad24%19]) with mapi id 14.03.0248.002; Sun, 4 Oct 2015 11:37:31 -0400
From: Stefan Fouant <Stefan.Fouant@corero.com>
To: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>, Christopher Morrow <morrowc.lists@gmail.com>
Thread-Topic: =?big5?B?W0RvdHNdILWqzmA6IE5leHQgRE9UUyBtZWV0aW5nIHRpbWU/?=
Thread-Index: AQHQ+k/513FiO5mtaU68J+wPEkglXp5S8fgAgAhcSAA=
Date: Sun, 4 Oct 2015 15:37:30 +0000
Message-ID: <D2369546.2EBD7%stefan.fouant@corero.com>
References: <35CD785E-8079-4CD8-93D2-DDBE98F1A776@arbor.net> <359EC4B99E040048A7131E0F4E113AFCD9516D26@marathon> <C02846B1344F344EB4FAA6FA7AF481F12AE8AD77@SZXEMA502-MBS.china.huawei.com> <CAL9jLaafJWKzprm7a=7FyJ6HG6ENPoyBTbKggbUr-t0ao6i9_w@mail.gmail.com> <0ED82EB8-45D4-4A48-98F4-2F34B28385F5@gmail.com>
In-Reply-To: <0ED82EB8-45D4-4A48-98F4-2F34B28385F5@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [96.90.223.42]
Content-Type: text/plain; charset="big5"
Content-ID: <39BFE8838BB33145B5F2E1D0F0B316FB@corero.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/Ppu7m8WuPvuWnuu3dvUdSJOxIZY>
Cc: "Roman D. Danyliw" <rdd@cert.org>, Andrew Mortensen <amortensen@arbor.net>, "Xialiang \(Frank\)" <frank.xialiang@huawei.com>, "dots@ietf.org" <dots@ietf.org>
Subject: Re: [Dots] =?big5?b?tarOYDogTmV4dCBET1RTIG1lZXRpbmcgdGltZT8=?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Oct 2015 15:37:37 -0000

T24gOS8yOC8xNSwgODo1NyBQTSwgIkRvdHMgb24gYmVoYWxmIG9mIEthdGhsZWVuIE1vcmlhcnR5
Ig0KPGRvdHMtYm91bmNlc0BpZXRmLm9yZyBvbiBiZWhhbGYgb2Yga2F0aGxlZW4ubW9yaWFydHku
aWV0ZkBnbWFpbC5jb20+DQp3cm90ZToNCg0KDQo+VGhlIG5leHQgSUVURiBtZWV0aW5nIHJ1bnMg
ZnJvbSBOb3ZlbWJlciAxLTYgaW4gWW9rb2hhbWEuICBUaGVyZSBpcyBubw0KPnBsYW4gZm9yIGEg
RE9UUyBtZWV0aW5nIG9uIHRoZSBPY3RvYmVyIGRhdGVzIGxpc3RlZCBiZWxvdy4NCj4NCj5UaGUg
YWdlbmRhIGlzIGJlaW5nIHdvcmtlZCBvbiBhbmQgd2lsbCBiZSBwdWJsaXNoZWQgb25jZSB3ZSBk
ZWNvbmZsaWN0IGENCj5mZXcgc2Vzc2lvbnMgYmFzZWQgb24gcmVxdWVzdHMgYW5kIGtub3duIGNv
bmZsaWN0cy4NCg0KSSBzZWUgdGhlIGFnZW5kYSBoYXMgYmVlbiBwdWJsaXNoZWQuIEl0IGxvb2tz
IGxpa2UgdGhlIG1lZXRpbmcgaXMNCnNjaGVkdWxlZCBmb3IgVHVlc2RheSBhZnRlcm5vb24gKDEx
LzAzLzE1KSBmcm9tIDEzMDAgLT4gMTUwMCBocnMuIGluIHJvb20NCjUwMS4NCg0KU3RlZmFuIEZv
dWFudA0KSk5DSUUtU0VDLCBKTkNJRS1TUCwgSk5DSUUtRU5ULCBKTkNJLCBDSVNTUA0KU2VuaW9y
IFNlY3VyaXR5IEVuZ2luZWVyDQpDb3Jlcm8gTmV0d29yayBTZWN1cml0eQ0KTW9iaWxlOiArMS43
MDMuNjI1LjYyNDMNCg0K


From nobody Sun Oct  4 09:06:48 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 861A01B3311 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 09:06:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -96.364
X-Spam-Level: 
X-Spam-Status: No, score=-96.364 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Jo9ITb5R5hYw for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 09:06:45 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 10DC31B330D for <dots@ietf.org>; Sun,  4 Oct 2015 09:06:45 -0700 (PDT)
Received: from [192.168.178.32] (x590f9529.dyn.telefonica.de [89.15.149.41]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id B9A0862DD7; Sun,  4 Oct 2015 18:06:42 +0200 (CEST)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=hgZwd+AlvECICWjKQxs60p986K0S2ilnLA4u/rtVHnAdYCdc7J9nERZ6/jJn5rCovHsRLIRsR/gXgjlw8K7znnF6ZKRdGXN9GUCactIOqF2hr5/Z7lQkB3CFjh/kO2FoSz+fMiUd0CeAbQDRkEMY/mxk21euM51SXwjKSGvqTY0=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type;
Message-ID: <56114E91.2090108@gondrom.org>
Date: Sun, 04 Oct 2015 18:06:41 +0200
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: Stefan.Fouant@corero.com, morrowc.lists@gmail.com
References: <35CD785E-8079-4CD8-93D2-DDBE98F1A776@arbor.net> <359EC4B99E040048A7131E0F4E113AFCD9516D26@marathon> <C02846B1344F344EB4FAA6FA7AF481F12AE8AD77@SZXEMA502-MBS.china.huawei.com> <CAL9jLaafJWKzprm7a=7FyJ6HG6ENPoyBTbKggbUr-t0ao6i9_w@mail.gmail.com> <0ED82EB8-45D4-4A48-98F4-2F34B28385F5@gmail.com> <D2369546.2EBD7%stefan.fouant@corero.com>
In-Reply-To: <D2369546.2EBD7%stefan.fouant@corero.com>
Content-Type: multipart/alternative; boundary="------------010408080207000600060602"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/EANUHjL00qoJLGKNbzPT0kCYjN8>
Cc: rdd@cert.org, amortensen@arbor.net, kathleen.moriarty.ietf@gmail.com, frank.xialiang@huawei.com, dots@ietf.org
Subject: Re: [Dots] =?utf-8?b?562U5aSNOiBOZXh0IERPVFMgbWVldGluZyB0aW1lPw==?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Oct 2015 16:06:46 -0000

This is a multi-part message in MIME format.
--------------010408080207000600060602
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

Stefan, dear WG,

that is correct.
The _*preliminary*_ agenda lists the DOTS meeting for:
Tuesday, Nov-3 at 13:00-15:00 (JST).

Please note that the agenda is still _*preliminary*_ and not fixed at 
this time, as there may still be changes due to WG rescheduling. The 
final agenda will be confirmed on Oct-9.

Best regards and looking forward to seeing you all in Yokohama

Tobias

(co-chair DOTS)


On 04/10/15 17:37, Stefan Fouant wrote:
>
> I see the agenda has been published. It looks like the meeting is
> scheduled for Tuesday afternoon (11/03/15) from 1300 -> 1500 hrs. in room
> 501.
>
> Stefan Fouant
> JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNCI, CISSP
> Senior Security Engineer
> Corero Network Security
> Mobile: +1.703.625.6243
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--------------010408080207000600060602
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Stefan, dear WG, <br>
    <br>
    that is correct. <br>
    The <u><b>preliminary</b></u> agenda lists the DOTS meeting for: <br>
    Tuesday, Nov-3 at 13:00-15:00 (JST). <br>
    <br>
    Please note that the agenda is still <u><b>preliminary</b></u> and
    not fixed at this time, as there may still be changes due to WG
    rescheduling. The final agenda will be confirmed on Oct-9. <br>
    <br>
    Best regards and looking forward to seeing you all in Yokohama<br>
    <br>
    Tobias<br>
    <br>
    (co-chair DOTS) <br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 04/10/15 17:37, Stefan Fouant wrote:<br>
    </div>
    <blockquote cite="mid:D2369546.2EBD7%25stefan.fouant@corero.com"
      type="cite"><br>
      <pre wrap="">
I see the agenda has been published. It looks like the meeting is
scheduled for Tuesday afternoon (11/03/15) from 1300 -&gt; 1500 hrs. in room
501.

Stefan Fouant
JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNCI, CISSP
Senior Security Engineer
Corero Network Security
Mobile: +1.703.625.6243

_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------010408080207000600060602--


From nobody Sun Oct  4 09:20:56 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1CB341B3393 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 09:20:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -94.765
X-Spam-Level: 
X-Spam-Status: No, score=-94.765 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HQmkZ9gfG5N7 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 09:20:52 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D55381B3361 for <dots@ietf.org>; Sun,  4 Oct 2015 09:18:43 -0700 (PDT)
Received: from [192.168.178.32] (x590f9529.dyn.telefonica.de [89.15.149.41]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 216A462DD7; Sun,  4 Oct 2015 18:18:42 +0200 (CEST)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=rL3iJVzlCmKNszXXfZXTtpns3JUI4vuYTiItjFyrKnw3FN2+F3JLO/qikoURS3kWxyf0gj+Wy+3buJT2RajP9d4uZXAt4NeAQyFdhtHAwCZHAw2BC4r9HsYKogggr5ZpSYrSJrhTXZxAcDDRf62i3ZJSNzCWhvdM7E0sCkwTp7c=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type;
Message-ID: <56115161.6030107@gondrom.org>
Date: Sun, 04 Oct 2015 18:18:41 +0200
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: mirkovic@isi.edu, rdobbins@arbor.net
References: <5603E6F4.5040407@htt-consult.com> <009901d0f6c9$8821cbc0$98656340$@jpshallow.com> <10e4a13c8d0a4cdcb76d38eb4f29aa3d@XCH-RCD-017.cisco.com> <CAL9jLaY_m89j2XAREtH+axEO_XjQm3LhaRjMZZB9p3ZN_wkTHQ@mail.gmail.com> <560451D3.7080502@htt-consult.com> <D229CB2A.2D3FC%stefan.fouant@corero.com> <560454E5.1070602@htt-consult.com> <5B01B3B3-826E-47D4-8D85-597823EBCA28@arbor.net> <CAO-aDqzhZ+yMqNK_EFDOX3yXWR=rO+a-m5zC67_TVkPFqk3gXA@mail.gmail.com> <BF29A213-8013-4DDF-98A5-BD31202EDC4E@arbor.net> <CAO-aDqw9NKXDKMQ0srLnzrWHr6FwVXuWMhZcNmQ_xo=1Cu2b5g@mail.gmail.com>
In-Reply-To: <CAO-aDqw9NKXDKMQ0srLnzrWHr6FwVXuWMhZcNmQ_xo=1Cu2b5g@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------050306040308010908080009"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/MJSChpFevGbD6905ED8bEtNTll8>
Cc: dots@ietf.org
Subject: Re: [Dots] How constrained due to attack congestion
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Oct 2015 16:20:55 -0000

This is a multi-part message in MIME format.
--------------050306040308010908080009
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit

<WG chair hat = off>

I like to strongly second Jelena's point.
Our WG charter covers a variety of aspects. Use cases and requirements 
are a good way to explore what is the problem and what needs to be done. 
And then the WG can group and prioritise them. When in doubt, I rather 
like to see more use cases listed, than editors drop use cases because 
they felt they are not likely.

Equally I encourage all WG members to review the upcoming use case and 
requirements drafts for elements that may still be missing and 
constructively raise these on the list so we can include them in future 
versions.

Best regards, Tobias




On 25/09/15 19:18, Jelena Mirkovic wrote:
> My point was not that we should wait or serialize. Instead I was 
> saying that we need not exclude use cases. We should list all/most 
> possible use cases and then designing protocol *modes* to work for 
> each. Even if some cases seem less likely to some of us. They may 
> become more likely in some environments.
>
>
>
> =========================
>
> Jelena Mirkovic
> Research Faculty
> USC Information Sciences Institute
> 4676 Admiralty Way, Suite 1001
> Marina del Rey, CA 90292
> 310-448-9170
>
>
> On Thu, Sep 24, 2015 at 5:39 PM, Roland Dobbins <rdobbins@arbor.net 
> <mailto:rdobbins@arbor.net>> wrote:
>
>     On 25 Sep 2015, at 7:36, Jelena Mirkovic wrote:
>
>         It really sounds as if we'd need to start with use cases and
>         work to implementations, then turn back, revisit, rehash, etc.
>
>
>     If we were starting from first principles in an intellectual
>     vacuum, yes.
>
>     Fortunately, we aren't.
>
>     We've already discussed in a reasonable degree of detail the broad
>     requirements, and we've also discussed the broad requirements;
>     couple that with the skills and experience of those who're
>     participating in this effort, and we can start at each and work
>     simultaneously towards the middle.
>
>
>     -----------------------------------
>     Roland Dobbins <rdobbins@arbor.net <mailto:rdobbins@arbor.net>>
>
>     _______________________________________________
>     Dots mailing list
>     Dots@ietf.org <mailto:Dots@ietf.org>
>     https://www.ietf.org/mailman/listinfo/dots
>
>
>
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--------------050306040308010908080009
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">&lt;WG chair hat = off&gt;<br>
      <br>
      I like to strongly second Jelena's point. <br>
      Our WG charter covers a variety of aspects. Use cases and
      requirements are a good way to explore what is the problem and
      what needs to be done. And then the WG can group and prioritise
      them. When in doubt, I rather like to see more use cases listed,
      than editors drop use cases because they felt they are not likely.
      <br>
      <br>
      Equally I encourage all WG members to review the upcoming use case
      and requirements drafts for elements that may still be missing and
      constructively raise these on the list so we can include them in
      future versions. <br>
      <br>
      Best regards, Tobias<br>
      <br>
      <br>
      <br>
    </font><br>
    <div class="moz-cite-prefix">On 25/09/15 19:18, Jelena Mirkovic
      wrote:<br>
    </div>
    <blockquote
cite="mid:CAO-aDqw9NKXDKMQ0srLnzrWHr6FwVXuWMhZcNmQ_xo=1Cu2b5g@mail.gmail.com"
      type="cite">
      <div dir="ltr">My point was not that we should wait or serialize.
        Instead I was saying that we need not exclude use cases. We
        should list all/most possible use cases and then designing
        protocol *modes* to work for each. Even if some cases seem less
        likely to some of us. They may become more likely in some
        environments.
        <div><br>
        </div>
        <div><br>
        </div>
      </div>
      <div class="gmail_extra"><br clear="all">
        <div>
          <div class="gmail_signature">
            <div dir="ltr">
              <p>=========================</p>
              <p>Jelena Mirkovic<br>
                <span style="font-size:12.6666669845581px">Research
                  Faculty<br>
                </span><span style="font-size:12.6666669845581px">USC
                  Information Sciences Institute<br>
                </span><span style="font-size:12.6666669845581px">4676
                  Admiralty Way, Suite 1001<br>
                </span><span style="font-size:12.6666669845581px">Marina
                  del Rey, CA 90292<br>
                </span><span style="font-size:12.6666669845581px">310-448-9170</span></p>
            </div>
          </div>
        </div>
        <br>
        <div class="gmail_quote">On Thu, Sep 24, 2015 at 5:39 PM, Roland
          Dobbins <span dir="ltr">&lt;<a moz-do-not-send="true"
              href="mailto:rdobbins@arbor.net" target="_blank">rdobbins@arbor.net</a>&gt;</span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex"><span
              class="">On 25 Sep 2015, at 7:36, Jelena Mirkovic wrote:<br>
              <br>
              <blockquote class="gmail_quote" style="margin:0 0 0
                .8ex;border-left:1px #ccc solid;padding-left:1ex">
                It really sounds as if we'd need to start with use cases
                and work to implementations, then turn back, revisit,
                rehash, etc.<br>
              </blockquote>
              <br>
            </span>
            If we were starting from first principles in an intellectual
            vacuum, yes.<br>
            <br>
            Fortunately, we aren't.<br>
            <br>
            We've already discussed in a reasonable degree of detail the
            broad requirements, and we've also discussed the broad
            requirements; couple that with the skills and experience of
            those who're participating in this effort, and we can start
            at each and work simultaneously towards the middle.
            <div class="HOEnZb">
              <div class="h5"><br>
                <br>
                -----------------------------------<br>
                Roland Dobbins &lt;<a moz-do-not-send="true"
                  href="mailto:rdobbins@arbor.net" target="_blank">rdobbins@arbor.net</a>&gt;<br>
                <br>
                _______________________________________________<br>
                Dots mailing list<br>
                <a moz-do-not-send="true" href="mailto:Dots@ietf.org"
                  target="_blank">Dots@ietf.org</a><br>
                <a moz-do-not-send="true"
                  href="https://www.ietf.org/mailman/listinfo/dots"
                  rel="noreferrer" target="_blank">https://www.ietf.org/mailman/listinfo/dots</a><br>
              </div>
            </div>
          </blockquote>
        </div>
        <br>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------050306040308010908080009--


From nobody Sun Oct  4 12:11:14 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1C4811A0111 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 12:11:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -94.765
X-Spam-Level: 
X-Spam-Status: No, score=-94.765 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q8VIJT8QLlol for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 12:11:10 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D8431A011B for <dots@ietf.org>; Sun,  4 Oct 2015 12:11:09 -0700 (PDT)
Received: from [192.168.178.32] (x590f9529.dyn.telefonica.de [89.15.149.41]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 6FB2162DD7; Sun,  4 Oct 2015 21:11:07 +0200 (CEST)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=mt7H3X/WMO+cJQQAoA2AC1LtUSlb75mf/I/zFsef79vneEAdgIU4XpMsSfjRjTH50+MejsaT+TGtYeArbhw6HvUbHkS2a7Hfed+P/DQsTYqxwIY8ZbnmK0Wqv0hvMbbKj3xIcp0cGJmHn/xrRquGT9n2ue+q/8Pn18VWghhPziI=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:Content-Type;
Message-ID: <561179CA.3020107@gondrom.org>
Date: Sun, 04 Oct 2015 21:11:06 +0200
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: dots@ietf.org
Content-Type: multipart/alternative; boundary="------------040507080407030902080005"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/DUryaD-SBXc5O0eaR2w9udMBBjs>
Cc: rdd@cert.org
Subject: [Dots] Reminder on the charter of DOTS and that multiple scenarios are in scope
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Oct 2015 19:11:13 -0000

This is a multi-part message in MIME format.
--------------040507080407030902080005
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Dear WG fellows,

over the last few weeks, I have noticed on one or two occasions that 
individuals may have claimed on the mailing-list that some use cases 
would be out-of-scope for the DOTS WG. Sometimes these assertions have 
been made ignoring our published and well-defined WG charter.
I recognise that some people may not yet have so much experience working 
within the IETF community or that from the perspective of individual 
companies there may be incentives to exclude certain use cases that are 
not relevant to the individual company's business.

However, I like to remind us all that:
1. We are participating in the IETF as individuals, seeking the best 
overall technical solution based on rough consensus and running code.
2. Our WG belongs to all equally and we do have WG consensus on the 
charter as published.
If you are not sure about the charter, please take a read here: 
http://datatracker.ietf.org/wg/dots/charter/
(as excerpt the first sentence from the charter: "The aim of DDoS Open 
Threat Signaling (DOTS) is to develop a standards based approach for the 
realtime signaling of DDoS related telemetry and threat handling 
requests and data between elements concerned with DDoS attack detection, 
classification, traceback, and mitigation.")

I am very pleased with all contributions and all the great discussions 
happening here on the mailing-list. Our charter is well crafted and well 
defined. I hope going forward we could simply follow our great charter 
and focus on the actual work. We should be careful to avoid individual 
attempts of re-interpretations based on company perspectives about what 
would be out-of-scope of the WG.

And I like to explicitly welcome and encourage all contributions that 
are within our published charter. And if you have any questions about 
IETF process, I will be happy to assist with explanations going forward. 
Please just drop me a note.

Thank you for your participation in the DOTS WG and I am very much 
looking forward to the upcoming use case and requirements drafts and 
hopefully the soon following protocol drafts.

Best regards,

Tobias (co-chair)




--------------040507080407030902080005
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">Dear WG fellows, <br>
      <br>
      over the last few weeks, I have noticed on one or two occasions
      that individuals may have claimed on the mailing-list that some
      use cases would be out-of-scope for the DOTS WG. Sometimes these
      assertions have been made ignoring our published and well-defined
      WG charter. <br>
    </font><font face="Arial">I recognise that some people may not yet
      have so much experience working within the IETF community or that
      from the perspective of individual companies there may be
      incentives to exclude certain use cases that are not relevant to
      the individual company's business. <br>
      <br>
      However, I like to remind us all that: <br>
      1. We are participating in the IETF as individuals, seeking the
      best overall technical solution based on rough consensus and
      running code. <br>
      2. Our WG belongs to all equally and we do have WG consensus on
      the charter as published. <br>
      If you are not sure about the charter, please take a read here: <a
        href="http://datatracker.ietf.org/wg/dots/charter/">http://datatracker.ietf.org/wg/dots/charter/
      </a><br>
      (as excerpt the first sentence from the charter: "The aim of DDoS
      Open Threat Signaling (DOTS) is to develop a standards based
      approach for the realtime signaling of DDoS related telemetry and
      threat handling requests and data between elements concerned with
      DDoS attack detection, classification, traceback, and
      mitigation.")<br>
      <br>
      I am very pleased with all contributions and all the great
      discussions happening here on the mailing-list. Our charter is
      well crafted and well defined. I hope going forward we could
      simply follow our great charter and focus on the actual work. We
      should be careful to avoid </font><font face="Arial"><font
        face="Arial">individual attempts of </font>re-interpretations
      based on company perspectives about what would be out-of-scope of
      the WG. <br>
      <br>
      And I like to explicitly welcome and encourage all contributions
      that are within our published charter. </font><font face="Arial"><font
        face="Arial">And if you have any questions about IETF process, I
        will be happy to assist with explanations going forward. Please
        just drop me a note. <br>
      </font><br>
      Thank you for your participation in the DOTS WG and I am very much
      looking forward to the upcoming use case and requirements drafts
      and hopefully the soon following protocol drafts. <br>
      <br>
      Best regards, <br>
      <br>
      Tobias (co-chair)<br>
      <br>
      <br>
      <br>
    </font>
  </body>
</html>

--------------040507080407030902080005--


From nobody Sun Oct  4 12:19:09 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEB631A21B0 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 12:19:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -96.664
X-Spam-Level: 
X-Spam-Status: No, score=-96.664 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WMzX5gMlUOHV for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 12:19:06 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 042D91A00CF for <dots@ietf.org>; Sun,  4 Oct 2015 12:19:06 -0700 (PDT)
Received: from [192.168.178.32] (x590f9529.dyn.telefonica.de [89.15.149.41]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 2B06462DD7; Sun,  4 Oct 2015 21:19:03 +0200 (CEST)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=Fp/ZwtmD0S1Kazq1EbPv4y9wzVJ8udP0NSmPAmExLiOzrB8eAopExvXI0k+B4+IgfNDZGeul14U4LXp7GqmlSBeInwI02yN4gHfbvTOJxpPFclWFqXPLjfjKZoC5EX+w1zXc5UC2zjSXFF8bbG8tvQYzwSpQfaS5dCJYQE03O7c=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type;
Message-ID: <56117BA6.5090005@gondrom.org>
Date: Sun, 04 Oct 2015 21:19:02 +0200
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: nteague@verisign.com
References: <359EC4B99E040048A7131E0F4E113AFCD94F1C56@marathon> <55D01F5E.4070009@gondrom.org> <55DDA4A9.3050603@inria.fr> <55DF03A4.8020105@cisco.com> <D20A403F.25E7B%dacheng.zdc@alibaba-inc.com> <55E4D60A.50002@gondrom.org> <D2138225.12781%nteague@verisign.com>
In-Reply-To: <D2138225.12781%nteague@verisign.com>
Content-Type: multipart/alternative; boundary="------------080105050209060301020507"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/lycuBVsUsDb4gSZTPdwGQKyA6nI>
Cc: dots@ietf.org
Subject: Re: [Dots] DOTS: next steps - call for editor volunteers for use case draft and requirements draft
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Oct 2015 19:19:07 -0000

This is a multi-part message in MIME format.
--------------080105050209060301020507
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi,

sorry for my late reply on this.

As I also sent in comments to some of the editors, preferably, the WG 
would self-organise for design teams as needed. If design teams are 
formed, they should be open to everyone interested in participating.

My suggestion would be that the draft editor teams each create a first 
00-version / strawman ASAP and then could e.g. organise an open call 
where people interested in the "design team" work can freely join.

At this moment, all design discussions should be going over the public 
mailing-list. (i.e. no separate mailing-lists are necessary). This 
allows for transparency and that the WG can better trace when issues 
have been raised and that they have been properly addressed.

Best regards,

Tobias (co-chair)


On 07/09/15 19:09, Teague, Nik wrote:
> Hi,
>
> On 31/08/2015 23:32, "Dots on behalf of Tobias Gondrom"
> <dots-bounces@ietf.org on behalf of tobias.gondrom@gondrom.org> wrote:
>
>> Dear all,
>>
>> apologies. Roman and I are currently still going through the (long) list
>> of editing volunteers. Which is a great place to be in for our WG. I
>> guess, we should be done by tomorrow.
>>
>>
>> In addition to the editing volunteers, I agree that design teams for the
>> two drafts might be useful. Always keep in mind that the editor's duty is
>> to capture the input from the WG and write it down. So everyone can
>> equally contribute. And a design team to work
>> out the details sounds useful.
> How close are we to getting this underway?  I’m keen as I can see others
> are to get things moving and it would be great if we can have some solid
> contributions/discussions going before the interim meeting.
>
> Do you have any ideas regarding design teams or we can self organise?
>
> Thanks,
>
> -Nik
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--------------080105050209060301020507
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">Hi, <br>
      <br>
      sorry for my late reply on this. <br>
      <br>
      As I also sent in comments to some of the editors, preferably, the
      WG would self-organise for design teams as needed. If design teams
      are formed, they should be open to everyone interested in
      participating. <br>
      <br>
      My suggestion would be that the draft editor teams each create a
      first 00-version / strawman ASAP and then could e.g. organise an
      open call where people interested in the "design team" work can
      freely join. <br>
      <br>
      At this moment, all design discussions should be going over the
      public mailing-list. (i.e. no separate mailing-lists are
      necessary). This allows for transparency and that the WG can
      better trace when issues have been raised and that they have been
      properly addressed. <br>
      <br>
      Best regards, <br>
      <br>
      Tobias (co-chair)<br>
      <br>
      <br>
    </font>
    <div class="moz-cite-prefix">On 07/09/15 19:09, Teague, Nik wrote:<br>
    </div>
    <blockquote cite="mid:D2138225.12781%25nteague@verisign.com"
      type="cite">
      <pre wrap="">Hi,

On 31/08/2015 23:32, "Dots on behalf of Tobias Gondrom"
<a class="moz-txt-link-rfc2396E" href="mailto:dots-bounces@ietf.orgonbehalfoftobias.gondrom@gondrom.org">&lt;dots-bounces@ietf.org on behalf of tobias.gondrom@gondrom.org&gt;</a> wrote:

</pre>
      <blockquote type="cite">
        <pre wrap="">Dear all, 

apologies. Roman and I are currently still going through the (long) list
of editing volunteers. Which is a great place to be in for our WG. I
guess, we should be done by tomorrow.


In addition to the editing volunteers, I agree that design teams for the
two drafts might be useful. Always keep in mind that the editor's duty is
to capture the input from the WG and write it down. So everyone can
equally contribute. And a design team to work
out the details sounds useful.
</pre>
      </blockquote>
      <pre wrap="">
How close are we to getting this underway?  I’m keen as I can see others
are to get things moving and it would be great if we can have some solid
contributions/discussions going before the interim meeting.

Do you have any ideas regarding design teams or we can self organise?

Thanks,

-Nik

_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------080105050209060301020507--


From nobody Sun Oct  4 22:34:04 2015
Return-Path: <xiaohong.deng@unsw.edu.au>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F3F61A8AB8 for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 22:34:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.607
X-Spam-Level: 
X-Spam-Status: No, score=-1.607 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HELO_EQ_AU=0.377, HOST_EQ_AU=0.327, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bcC0G0kFJsVz for <dots@ietfa.amsl.com>; Sun,  4 Oct 2015 22:34:01 -0700 (PDT)
Received: from INFPACM005.services.comms.unsw.edu.au (smtp.unsw.edu.au [149.171.193.32]) by ietfa.amsl.com (Postfix) with ESMTP id C69821A8AB6 for <dots@ietf.org>; Sun,  4 Oct 2015 22:34:00 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A2A7BQB8ChJW/zgaFKxeglpNVG4GrQyMV4QwgVohhXkCgSA5EwEBAQEBAQGBCoQkAQEBBG4LEAIBBQMNBAQBAQskMh0IAgQBDQUIDAeIEw3BP4RFAQEBAQEBAQMBAQEBAQEBAQEBAReGc4N4gQaEXDEHgxiBFAWNP4g9hReJVkeDcYMXDI5Dg28REgM9gkSBPj4zjAKBBgEBAQ
X-IPAS-Result: A2A7BQB8ChJW/zgaFKxeglpNVG4GrQyMV4QwgVohhXkCgSA5EwEBAQEBAQGBCoQkAQEBBG4LEAIBBQMNBAQBAQskMh0IAgQBDQUIDAeIEw3BP4RFAQEBAQEBAQMBAQEBAQEBAQEBAReGc4N4gQaEXDEHgxiBFAWNP4g9hReJVkeDcYMXDI5Dg28REgM9gkSBPj4zjAKBBgEBAQ
X-IronPort-AV: E=Sophos;i="5.17,636,1437400800";  d="scan'208,217";a="226203100"
Received: from unknown (HELO INFPWXH003.ad.unsw.edu.au) ([172.20.26.56]) by INFPACM005.services.comms.unsw.edu.au with ESMTP; 05 Oct 2015 16:33:58 +1100
Received: from INFPWXM010.ad.unsw.edu.au ([169.254.4.74]) by INFPWXH003.ad.unsw.edu.au ([172.20.26.56]) with mapi id 14.03.0248.002; Mon, 5 Oct 2015 16:33:58 +1100
From: Xiaohong Deng <xiaohong.deng@unsw.edu.au>
To: Tobias Gondrom <tobias.gondrom@gondrom.org>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] Reminder on the charter of DOTS and that multiple scenarios are in scope
Thread-Index: AQHQ/tiFIuh44XFJv0epb+/Pu8kCEp5cVu5r
Date: Mon, 5 Oct 2015 05:33:56 +0000
Message-ID: <36ADAEDEF1F28546BC414651D641DDAB0EDD73E0@INFPWXM010.ad.unsw.edu.au>
References: <561179CA.3020107@gondrom.org>
In-Reply-To: <561179CA.3020107@gondrom.org>
Accept-Language: en-GB, en-AU, en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [149.171.135.10]
Content-Type: multipart/alternative; boundary="_000_36ADAEDEF1F28546BC414651D641DDAB0EDD73E0INFPWXM010aduns_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/HV2_GTRyDnDDMo2M71X9qgHC-js>
Cc: "rdd@cert.org" <rdd@cert.org>
Subject: Re: [Dots] Reminder on the charter of DOTS and that multiple scenarios are in scope
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Oct 2015 05:34:03 -0000

--_000_36ADAEDEF1F28546BC414651D641DDAB0EDD73E0INFPWXM010aduns_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Thanks Chair for clarifying that this "out-of-scope" claim is personal opin=
ion but NOT WG consensus, and pointing out where we are heading for - addre=
ssing multiple important use cases to better tackle the problem statement, =
from IETF point of view, by and large.

I think this clarification helps both those who are not familiar with IETF =
process yet willing to contribute and those who could use a bit catch up wi=
th mailing-list...

Cheers,
Xiaohong

________________________________
From: Dots [dots-bounces@ietf.org] on behalf of Tobias Gondrom [tobias.gond=
rom@gondrom.org]
Sent: 05 October 2015 06:11
To: dots@ietf.org
Cc: rdd@cert.org
Subject: [Dots] Reminder on the charter of DOTS and that multiple scenarios=
 are in scope

Dear WG fellows,

over the last few weeks, I have noticed on one or two occasions that indivi=
duals may have claimed on the mailing-list that some use cases would be out=
-of-scope for the DOTS WG. Sometimes these assertions have been made ignori=
ng our published and well-defined WG charter.
I recognise that some people may not yet have so much experience working wi=
thin the IETF community or that from the perspective of individual companie=
s there may be incentives to exclude certain use cases that are not relevan=
t to the individual company's business.

However, I like to remind us all that:
1. We are participating in the IETF as individuals, seeking the best overal=
l technical solution based on rough consensus and running code.
2. Our WG belongs to all equally and we do have WG consensus on the charter=
 as published.
If you are not sure about the charter, please take a read here: http://data=
tracker.ietf.org/wg/dots/charter/
(as excerpt the first sentence from the charter: "The aim of DDoS Open Thre=
at Signaling (DOTS) is to develop a standards based approach for the realti=
me signaling of DDoS related telemetry and threat handling requests and dat=
a between elements concerned with DDoS attack detection, classification, tr=
aceback, and mitigation.")

I am very pleased with all contributions and all the great discussions happ=
ening here on the mailing-list. Our charter is well crafted and well define=
d. I hope going forward we could simply follow our great charter and focus =
on the actual work. We should be careful to avoid individual attempts of re=
-interpretations based on company perspectives about what would be out-of-s=
cope of the WG.

And I like to explicitly welcome and encourage all contributions that are w=
ithin our published charter. And if you have any questions about IETF proce=
ss, I will be happy to assist with explanations going forward. Please just =
drop me a note.

Thank you for your participation in the DOTS WG and I am very much looking =
forward to the upcoming use case and requirements drafts and hopefully the =
soon following protocol drafts.

Best regards,

Tobias (co-chair)




--_000_36ADAEDEF1F28546BC414651D641DDAB0EDD73E0INFPWXM010aduns_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html dir=3D"ltr">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" id=3D"owaParaStyle"></style>
</head>
<body bgcolor=3D"#FFFFFF" fpstyle=3D"1" ocsi=3D"0">
<div style=3D"direction: ltr;font-family: Tahoma;color: #000000;font-size: =
10pt;">Thanks Chair for&nbsp;clarifying<span style=3D"font-size: 13.3333330=
154419px;">&nbsp;that this</span>&nbsp;&quot;out-of-scope&quot; claim is pe=
rsonal opinion but NOT WG consensus, and&nbsp;<span style=3D"font-size: 13.=
3333330154419px;">pointing
 out&nbsp;</span><span style=3D"font-size: 10pt;">where we are heading for =
- addressing multiple important use cases to better tackle the problem stat=
ement, from IETF point of view, by and large.</span>
<div>
<div><br>
</div>
<div>I think this clarification helps both those who are not familiar with =
IETF process yet willing to contribute and those who could use a bit catch =
up with mailing-list...</div>
<div><br>
</div>
<div>Cheers,</div>
<div>Xiaohong</div>
<div><br>
</div>
<div>
<div style=3D"font-family: Times New Roman; color: #000000; font-size: 16px=
">
<hr tabindex=3D"-1">
<div id=3D"divRpF230063" style=3D"direction: ltr;"><font face=3D"Tahoma" si=
ze=3D"2" color=3D"#000000"><b>From:</b> Dots [dots-bounces@ietf.org] on beh=
alf of Tobias Gondrom [tobias.gondrom@gondrom.org]<br>
<b>Sent:</b> 05 October 2015 06:11<br>
<b>To:</b> dots@ietf.org<br>
<b>Cc:</b> rdd@cert.org<br>
<b>Subject:</b> [Dots] Reminder on the charter of DOTS and that multiple sc=
enarios are in scope<br>
</font><br>
</div>
<div></div>
<div><font face=3D"Arial">Dear WG fellows, <br>
<br>
over the last few weeks, I have noticed on one or two occasions that indivi=
duals may have claimed on the mailing-list that some use cases would be out=
-of-scope for the DOTS WG. Sometimes these assertions have been made ignori=
ng our published and well-defined
 WG charter. <br>
</font><font face=3D"Arial">I recognise that some people may not yet have s=
o much experience working within the IETF community or that from the perspe=
ctive of individual companies there may be incentives to exclude certain us=
e cases that are not relevant to the
 individual company's business. <br>
<br>
However, I like to remind us all that: <br>
1. We are participating in the IETF as individuals, seeking the best overal=
l technical solution based on rough consensus and running code.
<br>
2. Our WG belongs to all equally and we do have WG consensus on the charter=
 as published.
<br>
If you are not sure about the charter, please take a read here: <a href=3D"=
http://datatracker.ietf.org/wg/dots/charter/" target=3D"_blank">
http://datatracker.ietf.org/wg/dots/charter/ </a><br>
(as excerpt the first sentence from the charter: &quot;The aim of DDoS Open=
 Threat Signaling (DOTS) is to develop a standards based approach for the r=
ealtime signaling of DDoS related telemetry and threat handling requests an=
d data between elements concerned with
 DDoS attack detection, classification, traceback, and mitigation.&quot;)<b=
r>
<br>
I am very pleased with all contributions and all the great discussions happ=
ening here on the mailing-list. Our charter is well crafted and well define=
d. I hope going forward we could simply follow our great charter and focus =
on the actual work. We should be
 careful to avoid </font><font face=3D"Arial"><font face=3D"Arial">individu=
al attempts of
</font>re-interpretations based on company perspectives about what would be=
 out-of-scope of the WG.
<br>
<br>
And I like to explicitly welcome and encourage all contributions that are w=
ithin our published charter.
</font><font face=3D"Arial"><font face=3D"Arial">And if you have any questi=
ons about IETF process, I will be happy to assist with explanations going f=
orward. Please just drop me a note.
<br>
</font><br>
Thank you for your participation in the DOTS WG and I am very much looking =
forward to the upcoming use case and requirements drafts and hopefully the =
soon following protocol drafts.
<br>
<br>
Best regards, <br>
<br>
Tobias (co-chair)<br>
<br>
<br>
<br>
</font></div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_36ADAEDEF1F28546BC414651D641DDAB0EDD73E0INFPWXM010aduns_--


From nobody Sun Oct 11 11:05:25 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7AA251B2C2E for <dots@ietfa.amsl.com>; Sun, 11 Oct 2015 11:05:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -95.264
X-Spam-Level: 
X-Spam-Status: No, score=-95.264 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qHkpD6dDJDfC for <dots@ietfa.amsl.com>; Sun, 11 Oct 2015 11:05:22 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1DBFA1B2C2B for <dots@ietf.org>; Sun, 11 Oct 2015 11:05:21 -0700 (PDT)
Received: from [192.168.178.32] (x5ce2e2ba.dyn.telefonica.de [92.226.226.186]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id F1E9363516; Sun, 11 Oct 2015 20:05:18 +0200 (CEST)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=2jwWRVOYyN++EEdp5hUOLwgXQsHXUV6bBmsbIih9MvIrkqtzmUeEaZ/6OzefPlTnV7TSNHEvtj64rIMIhne1IRNUqMyXU8hsC+17i+XEy6UoHF3Vam2jZrjte4lRCEvvX9BnVth7msRAwNzGCRIVbbBOtEeYsNDvY4rvmIwT3x8=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:X-Priority:References:In-Reply-To:X-Forwarded-Message-Id:Content-Type;
Message-ID: <561AA4DE.7000308@gondrom.org>
Date: Sun, 11 Oct 2015 20:05:18 +0200
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: dots@ietf.org
X-Priority: 2 (High)
References: <20151010012851.29540.89233.idtracker@ietfa.amsl.com>
In-Reply-To: <20151010012851.29540.89233.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20151010012851.29540.89233.idtracker@ietfa.amsl.com>
Content-Type: multipart/alternative; boundary="------------090802020200020205040909"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/r4_otakr_mrJO5Gz1bBT2T38MxQ>
Cc: rdd@cert.org
Subject: [Dots] DOTS session schedule confirmed for IETF 94 & call for agenda items
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 Oct 2015 18:05:24 -0000

This is a multi-part message in MIME format.
--------------090802020200020205040909
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Dear DOTS WG team,

our agenda slot for IETF 94 in Yokohama has been confirmed.

dots Session 1 (2:00:00)
     Tuesday Nov-3, Afternoon Session I 1300-1500
     Room Name: Room 501 size: 250

Please note:
*1. if you have a presentation or topic for our WG, please let Roman and 
myself know ASAP. **
*We are preparing the agenda draft until Oct-17 based on input we receive.

*2. Internet Draft submission cut-off (for all drafts, including -00) is 
on 2015-10-19 (Monday) by UTC 23:59*, upload using IETF ID Submission 
Tool. Please submit your drafts before that: 
https://datatracker.ietf.org/submit/
I am still looking for the new requirements and use cases drafts.
And as well for first protocol proposal drafts for our DOTS WG.

*If you like to present a topic, it is highly advisable to have 
submitted an updated draft before the deadline (Oct-19). **
*
Thanks and best regards,

Tobias  (co-chair DOTS)





--------------090802020200020205040909
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Dear DOTS WG team, <br>
    <br>
    our agenda slot for IETF 94 in Yokohama has been confirmed. <br>
    <br>
    dots Session 1 (2:00:00)<br>
        Tuesday Nov-3, Afternoon Session I 1300-1500<br>
        Room Name: Room 501 size: 250<br>
    <br>
    Please note: <br>
    <b>1. if you have a presentation or topic for our WG, please let
      Roman and myself know ASAP. </b><b><br>
    </b>We are preparing the agenda draft until Oct-17 based on input we
    receive. <br>
    <br>
    <b>2. Internet Draft submission cut-off (for all drafts, including
      -00) is on 2015-10-19 (Monday) by UTC 23:59</b>, upload using IETF
    ID Submission Tool. Please submit your drafts before that: <a
      href="https://datatracker.ietf.org/submit/">https://datatracker.ietf.org/submit/</a><br>
    I am still looking for the new requirements and use cases drafts. <br>
    And as well for first protocol proposal drafts for our DOTS WG. <br>
    <br>
    <b>If you like to present a topic, it is highly advisable to have
      submitted an updated draft before the deadline (Oct-19). </b><b><br>
    </b><br>
    Thanks and best regards, <br>
    <br>
    Tobias  (co-chair DOTS)<br>
    <br>
    <div class="moz-forward-container"><br>
      <br>
    </div>
    <br>
  </body>
</html>

--------------090802020200020205040909--


From nobody Sun Oct 18 19:11:22 2015
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E6F031A004A for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 19:11:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.911
X-Spam-Level: 
X-Spam-Status: No, score=-3.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4C2ntTOm9CWp for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 19:11:19 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3BF771A001A for <dots@ietf.org>; Sun, 18 Oct 2015 19:11:19 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml405-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BYY72814; Mon, 19 Oct 2015 02:11:17 +0000 (GMT)
Received: from SZXEMA413-HUB.china.huawei.com (10.82.72.72) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.235.1; Mon, 19 Oct 2015 03:11:17 +0100
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.77]) by SZXEMA413-HUB.china.huawei.com ([10.82.72.72]) with mapi id 14.03.0235.001; Mon, 19 Oct 2015 10:11:11 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRChKBgy392uVC4EubFSU1bnOiOZ5yEQAg
Date: Mon, 19 Oct 2015 02:11:11 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDE3@SZXEMA502-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.135.43.91]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/EG9tDEo5Jg7ooB0AC6NCKepwEek>
Subject: [Dots] =?utf-8?b?6L2s5Y+ROiBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24gZm9y?= =?utf-8?q?_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 02:11:21 -0000

SGkgYWxsLA0KV2Ugc3VibWl0IGEgLTAwIHZlcnNpb24gZHJhZnQgZm9yIGNsYXJpZnlpbmcgaG93
IHRvIHJldXNlIGN1cnJlbnQgSVBGSVggcHJvdG9jb2wgYW5kIGl0cyBJRXMgKHRvZ2V0aGVyIHdp
dGggc2V2ZXJhbCBuZXcgSUVzKSB0byBkZXRlY3QgbW9zdCBjb21tb24gbmV0d29yayBhdHRhY2tz
LCB3aGljaCBjYW4gYmUgdXNlZCBieSBET1RTIHByb3RvY29sLg0KSG9wZSB0aGlzIGRyYWZ0IGNh
biBiZSBwYXJ0IG9mIHRoZSBkaXNjdXNzaW9uIGFib3V0IGF0dGFjayB0ZWxlbWV0cnkgaW5mb3Jt
YXRpb24uDQoNCllvdXIgaW50ZXJlc3RzIGFuZCBjb21tZW50cyBhcmUgZ3JlYXRseSBhcHByZWNp
YXRlZCENCg0KQi5SLg0KRnJhbmsNCg0KLS0tLS3pgq7ku7bljp/ku7YtLS0tLQ0K5Y+R5Lu25Lq6
OiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmcgW21haWx0bzppbnRlcm5ldC1kcmFmdHNAaWV0Zi5v
cmddIA0K5Y+R6YCB5pe26Ze0OiAyMDE15bm0MTDmnIgxOeaXpSAxMDowNA0K5pS25Lu25Lq6OiBE
YWNoZW5nIFpoYW5nOyBEYUNoZW5nIFpoYW5nOyBGdXRpYW5mdTsgWGlhbGlhbmcgKEZyYW5rKTsg
bGltaW4gMDAyMjM5NjE7IGxpbWluIDAwMjIzOTYxOyBGdXRpYW5mdTsgWGlhbGlhbmcgKEZyYW5r
KQ0K5Li76aKYOiBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24gZm9yIGRyYWZ0LWZ1LWRvdHMtaXBm
aXgtZXh0ZW5zaW9uLTAwLnR4dA0KDQoNCkEgbmV3IHZlcnNpb24gb2YgSS1ELCBkcmFmdC1mdS1k
b3RzLWlwZml4LWV4dGVuc2lvbi0wMC50eHQNCmhhcyBiZWVuIHN1Y2Nlc3NmdWxseSBzdWJtaXR0
ZWQgYnkgTGlhbmcgWGlhIGFuZCBwb3N0ZWQgdG8gdGhlIElFVEYgcmVwb3NpdG9yeS4NCg0KTmFt
ZToJCWRyYWZ0LWZ1LWRvdHMtaXBmaXgtZXh0ZW5zaW9uDQpSZXZpc2lvbjoJMDANClRpdGxlOgkJ
SVBGSVggSUUgRXh0ZW5zaW9ucyBmb3IgRERvUyBBdHRhY2sgRGV0ZWN0aW9uDQpEb2N1bWVudCBk
YXRlOgkyMDE1LTEwLTE5DQpHcm91cDoJCUluZGl2aWR1YWwgU3VibWlzc2lvbg0KUGFnZXM6CQky
MQ0KVVJMOiAgICAgICAgICAgIGh0dHBzOi8vd3d3LmlldGYub3JnL2ludGVybmV0LWRyYWZ0cy9k
cmFmdC1mdS1kb3RzLWlwZml4LWV4dGVuc2lvbi0wMC50eHQNClN0YXR1czogICAgICAgICBodHRw
czovL2RhdGF0cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1mdS1kb3RzLWlwZml4LWV4dGVuc2lv
bi8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtZnUt
ZG90cy1pcGZpeC1leHRlbnNpb24tMDANCg0KDQpBYnN0cmFjdDoNCiAgIEFsdGhvdWdoIG1vc3Qg
b2YgdGhlIGV4aXN0aW5nIElQIEZsb3cgSW5mb3JtYXRpb24gRXhwb3J0IChJUEZJWCkNCiAgIElu
Zm9ybWF0aW9uIEVsZW1lbnRzIChJRXMpIGFyZSB1c2VmdWwgZm9yIG5ldHdvcmsgc2VjdXJpdHkN
CiAgIGluc3BlY3Rpb24sIHRoZXJlIGFyZSBzdGlsbCBzb21lIGdhcHMgZXhpc3RpbmcgdG8gaWRl
bnRpZnkgYSBudW1iZXINCiAgIG9mIGNhdGVnb3JpZXMgb2YgdGhlIGF0dGFja3MuICBUbyBmaWxs
IGluIHRoZSBnYXBzLCB0aGlzIGRvY3VtZW50DQogICBkZWZpbmVzIHNvbWUgbmV3IElQRklYIElF
cyBhbmQgZGVzY3JpYmVzIHRoZWlyIGZvcm1hdHMgZm9yDQogICBpbnNwZWN0aW5nIG5ldHdvcmsg
c2VjdXJpdHkuDQoNCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCg0KDQpQbGVhc2Ugbm90ZSB0
aGF0IGl0IG1heSB0YWtlIGEgY291cGxlIG9mIG1pbnV0ZXMgZnJvbSB0aGUgdGltZSBvZiBzdWJt
aXNzaW9uIHVudGlsIHRoZSBodG1saXplZCB2ZXJzaW9uIGFuZCBkaWZmIGFyZSBhdmFpbGFibGUg
YXQgdG9vbHMuaWV0Zi5vcmcuDQoNClRoZSBJRVRGIFNlY3JldGFyaWF0DQoNCg==


From nobody Sun Oct 18 19:14:52 2015
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A2421A0052 for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 19:14:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.911
X-Spam-Level: 
X-Spam-Status: No, score=-3.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id n_BqHCUE5zM9 for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 19:14:49 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7E8AC1A0056 for <dots@ietf.org>; Sun, 18 Oct 2015 19:14:48 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml404-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id CCS16860; Mon, 19 Oct 2015 02:14:47 +0000 (GMT)
Received: from SZXEMA413-HUB.china.huawei.com (10.82.72.72) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.235.1; Mon, 19 Oct 2015 03:14:46 +0100
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.77]) by SZXEMA413-HUB.china.huawei.com ([10.82.72.72]) with mapi id 14.03.0235.001; Mon, 19 Oct 2015 10:14:39 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: "Roman D. Danyliw" <rdd@cert.org>, "tobias.gondrom@gondrom.org" <tobias.gondrom@gondrom.org>
Thread-Topic: New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRChKBgy392uVC4EubFSU1bnOiOZ5yErmA
Date: Mon, 19 Oct 2015 02:14:38 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.135.43.91]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/giPu-zSJsev1l9GDvhEcCnIQ8TA>
Cc: "dots@ietf.org" <dots@ietf.org>
Subject: [Dots] =?utf-8?b?6L2s5Y+ROiBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24gZm9y?= =?utf-8?q?_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 02:14:50 -0000

SGkgRE9UUyBDaGFpcnMsDQpNYXkgSSByZXF1ZXN0IGZvciBhIDUgb3IgMTAgbWludXRlcyB0aW1l
IHNsb3QgZm9yIHByZXNlbnRpbmcgdGhlIGZvbGxvd2luZyBkcmFmdCwgYXMgYW4gaW5wdXQgZm9y
IHRoZSBkaXNjdXNzaW9uIGFib3V0IGF0dGFjayB0ZWxlbWV0cnkgaW5mb3JtYXRpb24/DQoNClRo
YW5rcyBhIGxvdCENCg0KQi5SLg0KRnJhbmsNCg0KLS0tLS3pgq7ku7bljp/ku7YtLS0tLQ0K5Y+R
5Lu25Lq6OiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmcgW21haWx0bzppbnRlcm5ldC1kcmFmdHNA
aWV0Zi5vcmddIA0K5Y+R6YCB5pe26Ze0OiAyMDE15bm0MTDmnIgxOeaXpSAxMDowNA0K5pS25Lu2
5Lq6OiBEYWNoZW5nIFpoYW5nOyBEYUNoZW5nIFpoYW5nOyBGdXRpYW5mdTsgWGlhbGlhbmcgKEZy
YW5rKTsgbGltaW4gMDAyMjM5NjE7IGxpbWluIDAwMjIzOTYxOyBGdXRpYW5mdTsgWGlhbGlhbmcg
KEZyYW5rKQ0K5Li76aKYOiBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24gZm9yIGRyYWZ0LWZ1LWRv
dHMtaXBmaXgtZXh0ZW5zaW9uLTAwLnR4dA0KDQoNCkEgbmV3IHZlcnNpb24gb2YgSS1ELCBkcmFm
dC1mdS1kb3RzLWlwZml4LWV4dGVuc2lvbi0wMC50eHQNCmhhcyBiZWVuIHN1Y2Nlc3NmdWxseSBz
dWJtaXR0ZWQgYnkgTGlhbmcgWGlhIGFuZCBwb3N0ZWQgdG8gdGhlIElFVEYgcmVwb3NpdG9yeS4N
Cg0KTmFtZToJCWRyYWZ0LWZ1LWRvdHMtaXBmaXgtZXh0ZW5zaW9uDQpSZXZpc2lvbjoJMDANClRp
dGxlOgkJSVBGSVggSUUgRXh0ZW5zaW9ucyBmb3IgRERvUyBBdHRhY2sgRGV0ZWN0aW9uDQpEb2N1
bWVudCBkYXRlOgkyMDE1LTEwLTE5DQpHcm91cDoJCUluZGl2aWR1YWwgU3VibWlzc2lvbg0KUGFn
ZXM6CQkyMQ0KVVJMOiAgICAgICAgICAgIGh0dHBzOi8vd3d3LmlldGYub3JnL2ludGVybmV0LWRy
YWZ0cy9kcmFmdC1mdS1kb3RzLWlwZml4LWV4dGVuc2lvbi0wMC50eHQNClN0YXR1czogICAgICAg
ICBodHRwczovL2RhdGF0cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1mdS1kb3RzLWlwZml4LWV4
dGVuc2lvbi8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJh
ZnQtZnUtZG90cy1pcGZpeC1leHRlbnNpb24tMDANCg0KDQpBYnN0cmFjdDoNCiAgIEFsdGhvdWdo
IG1vc3Qgb2YgdGhlIGV4aXN0aW5nIElQIEZsb3cgSW5mb3JtYXRpb24gRXhwb3J0IChJUEZJWCkN
CiAgIEluZm9ybWF0aW9uIEVsZW1lbnRzIChJRXMpIGFyZSB1c2VmdWwgZm9yIG5ldHdvcmsgc2Vj
dXJpdHkNCiAgIGluc3BlY3Rpb24sIHRoZXJlIGFyZSBzdGlsbCBzb21lIGdhcHMgZXhpc3Rpbmcg
dG8gaWRlbnRpZnkgYSBudW1iZXINCiAgIG9mIGNhdGVnb3JpZXMgb2YgdGhlIGF0dGFja3MuICBU
byBmaWxsIGluIHRoZSBnYXBzLCB0aGlzIGRvY3VtZW50DQogICBkZWZpbmVzIHNvbWUgbmV3IElQ
RklYIElFcyBhbmQgZGVzY3JpYmVzIHRoZWlyIGZvcm1hdHMgZm9yDQogICBpbnNwZWN0aW5nIG5l
dHdvcmsgc2VjdXJpdHkuDQoNCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCg0KDQpQbGVhc2Ug
bm90ZSB0aGF0IGl0IG1heSB0YWtlIGEgY291cGxlIG9mIG1pbnV0ZXMgZnJvbSB0aGUgdGltZSBv
ZiBzdWJtaXNzaW9uIHVudGlsIHRoZSBodG1saXplZCB2ZXJzaW9uIGFuZCBkaWZmIGFyZSBhdmFp
bGFibGUgYXQgdG9vbHMuaWV0Zi5vcmcuDQoNClRoZSBJRVRGIFNlY3JldGFyaWF0DQoNCg==


From nobody Sun Oct 18 20:18:46 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FDCA1A019B for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 20:18:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iGmVSnNoOPvV for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 20:18:43 -0700 (PDT)
Received: from mail-pa0-x231.google.com (mail-pa0-x231.google.com [IPv6:2607:f8b0:400e:c03::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 911831A0180 for <dots@ietf.org>; Sun, 18 Oct 2015 20:18:43 -0700 (PDT)
Received: by pasz6 with SMTP id z6so15772803pas.2 for <dots@ietf.org>; Sun, 18 Oct 2015 20:18:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-type; bh=04gBEZ3+vqENSJOQF6xoc1FD+8pS49cCE9V43KOwRqI=; b=UHOFlUBIUFbGPnHF3ZebWI1D2EmMBlRsKRV9DLC/A8nZkAIdfmoc8+KA5/9UXpdalH G4WUDWez/Yp6Y+509/iJUFx9mD4Jr8nTC9tOcb0r6f64vA2YakasieLEA2HMrcbbU/HA pzXdXEU1Z5rn03tb3YrijvpfssTUSTOq1iVUY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=04gBEZ3+vqENSJOQF6xoc1FD+8pS49cCE9V43KOwRqI=; b=ZjWVi8i9pt1vEzk0AglvK0y5wnP7ZH+ibLsI5ew9ErjYnRu263NJQ9G4MxrrW1Mw4J CYhmVnfg7G6BxUB3n0Na8DupHQwvp4v8pnrVPtnQwvZ604LCngN9mTCoC8ArWp1oJccj 30zY78pYZFkAbNEpXdQWmKulepSa0blycmSKJXlzyWyxIRng1v0L1SNZBUu90p2XhrlO 2AGyqTJHkmtYgo/YPmjgJWXOdKYcnT9k3UfvxfhrJCBg9FLEFDedqx86bsog27r6pf7I gxEoA+FTRj2afLJ8G4mHBBTqc7KSJcoLk5EyJOyqHNgzuq93hVXMoPa80su8gT/qVZjz ra1Q==
X-Gm-Message-State: ALoCoQltkVoAmcL7jpOPQetPt0yWHMyhsRYXw5wDZ9qQZgWh1qHCzb6vQblX2LHGOWmPJ6mkMdUS
X-Received: by 10.66.155.167 with SMTP id vx7mr9061587pab.127.1445224723132; Sun, 18 Oct 2015 20:18:43 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id ci2sm33204996pbc.66.2015.10.18.20.18.40 (version=TLSv1 cipher=RC4-SHA bits=128/128); Sun, 18 Oct 2015 20:18:42 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots <dots@ietf.org>
Date: Mon, 19 Oct 2015 10:18:38 +0700
Message-ID: <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net>
In-Reply-To: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/n1TdLHQc_6bI-_ztBkJjJoLNLjQ>
Cc: "Roman D. Danyliw" <rdd@cert.org>, Tobias Gondrom <tobias.gondrom@gondrom.org>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 03:18:45 -0000

On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:

> May I request for a 5 or 10 minutes time slot for presenting the 
> following draft, as an input for the discussion about attack telemetry 
> information?

 From the DOTS WG charter:

   The WG will, where appropriate, reuse or extend existing standard
   protocols and mechanisms (for example, IPFIX and its associated
   templating and extension mechanisms).

This language in the DOTS WG charter is not intended to suggest a 
general extension of any existing standards such as IPFIX; rather, it is 
intended to note that should an existing standard may be desirable for 
use within the context of threat signaling, the DOTS WG may request an 
extension of said standard to support the DOTS mission of 
standards-based threat signaling.

draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is 
wholly unconcerned with threat signaling.

 From the DOTS WG charter:

   Any modification of or extension to existing protocols must be in 
close coordination with the working
   groups responsible for the protocol being modified, and may be done 
in this working group after agreement
   with all the relevant WGs and responsible Area Directors.

The above criteria from the DOTS WG charter have not been fulfilled with 
regards to any proposed extension of IPFIX.

It is respectfully suggested to the chairs that this draft (as in its 
previous iteration) is more suited for the (currently Concluded) IPFIX 
WG, as it is not directly related to the potential use of IPFIX for 
threat signaling, but is more of a proposed general extension of IPFIX.  
As such, its authors would more profitably direct their efforts in this 
regard by petitioning for a reopening of the IPFIX WG.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Sun Oct 18 20:34:58 2015
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0366C1A0252 for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 20:34:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.078
X-Spam-Level: **
X-Spam-Status: No, score=2.078 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CHARSET_FARAWAY_HEADER=3.2, CN_BODY_35=0.339, MIME_8BIT_HEADER=0.3, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id garyscTn0ELr for <dots@ietfa.amsl.com>; Sun, 18 Oct 2015 20:34:54 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 000D41A0242 for <dots@ietf.org>; Sun, 18 Oct 2015 20:34:53 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml402-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BYY78204; Mon, 19 Oct 2015 03:34:52 +0000 (GMT)
Received: from SZXEMA413-HUB.china.huawei.com (10.82.72.72) by lhreml402-hub.china.huawei.com (10.201.5.241) with Microsoft SMTP Server (TLS) id 14.3.235.1; Mon, 19 Oct 2015 04:33:55 +0100
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.77]) by SZXEMA413-HUB.china.huawei.com ([10.82.72.72]) with mapi id 14.03.0235.001; Mon, 19 Oct 2015 11:33:49 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: Roland Dobbins <rdobbins@arbor.net>, dots <dots@ietf.org>
Thread-Topic: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRChKBgy392uVC4EubFSU1bnOiOZ5yErmA//+MtgCAAIcqYA==
Date: Mon, 19 Oct 2015 03:33:48 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net>
In-Reply-To: <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.135.43.91]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/o_t_0gYoA5wYrQOHKW5-5q8Gwg8>
Cc: "Roman D. Danyliw" <rdd@cert.org>, Tobias Gondrom <tobias.gondrom@gondrom.org>
Subject: [Dots] =?gb2312?b?tPC4tDogIE5ldyBWZXJzaW9uIE5vdGlmaWNhdGlvbiBm?= =?gb2312?b?b3IgZHJhZnQtZnUtZG90cy1pcGZpeC1leHRlbnNpb24tMDAudHh0?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 03:34:57 -0000

SGkgUm9sYW5kIGFuZCBhbGwsDQpTZWUgbXkgY2xhcmlmaWNhdGlvbnM6DQoNCi0tLS0t08q8/tSt
vP4tLS0tLQ0Kt6K8/sjLOiBEb3RzIFttYWlsdG86ZG90cy1ib3VuY2VzQGlldGYub3JnXSC0+rHt
IFJvbGFuZCBEb2JiaW5zDQq3osvNyrG85DogMjAxNcTqMTDUwjE5yNUgMTE6MTkNCsrVvP7Iyzog
ZG90cw0Ks63LzTogUm9tYW4gRC4gRGFueWxpdzsgVG9iaWFzIEdvbmRyb20NCtb3zOI6IFJlOiBb
RG90c10gTmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZvciBkcmFmdC1mdS1kb3RzLWlwZml4LWV4
dGVuc2lvbi0wMC50eHQNCg0KDQpPbiAxOSBPY3QgMjAxNSwgYXQgOToxNCwgWGlhbGlhbmcgKEZy
YW5rKSB3cm90ZToNCg0KPiBNYXkgSSByZXF1ZXN0IGZvciBhIDUgb3IgMTAgbWludXRlcyB0aW1l
IHNsb3QgZm9yIHByZXNlbnRpbmcgdGhlIA0KPiBmb2xsb3dpbmcgZHJhZnQsIGFzIGFuIGlucHV0
IGZvciB0aGUgZGlzY3Vzc2lvbiBhYm91dCBhdHRhY2sgdGVsZW1ldHJ5IA0KPiBpbmZvcm1hdGlv
bj8NCg0KIEZyb20gdGhlIERPVFMgV0cgY2hhcnRlcjoNCg0KICAgVGhlIFdHIHdpbGwsIHdoZXJl
IGFwcHJvcHJpYXRlLCByZXVzZSBvciBleHRlbmQgZXhpc3Rpbmcgc3RhbmRhcmQNCiAgIHByb3Rv
Y29scyBhbmQgbWVjaGFuaXNtcyAoZm9yIGV4YW1wbGUsIElQRklYIGFuZCBpdHMgYXNzb2NpYXRl
ZA0KICAgdGVtcGxhdGluZyBhbmQgZXh0ZW5zaW9uIG1lY2hhbmlzbXMpLg0KDQpUaGlzIGxhbmd1
YWdlIGluIHRoZSBET1RTIFdHIGNoYXJ0ZXIgaXMgbm90IGludGVuZGVkIHRvIHN1Z2dlc3QgYSBn
ZW5lcmFsIGV4dGVuc2lvbiBvZiBhbnkgZXhpc3Rpbmcgc3RhbmRhcmRzIHN1Y2ggYXMgSVBGSVg7
IHJhdGhlciwgaXQgaXMgaW50ZW5kZWQgdG8gbm90ZSB0aGF0IHNob3VsZCBhbiBleGlzdGluZyBz
dGFuZGFyZCBtYXkgYmUgZGVzaXJhYmxlIGZvciB1c2Ugd2l0aGluIHRoZSBjb250ZXh0IG9mIHRo
cmVhdCBzaWduYWxpbmcsIHRoZSBET1RTIFdHIG1heSByZXF1ZXN0IGFuIGV4dGVuc2lvbiBvZiBz
YWlkIHN0YW5kYXJkIHRvIHN1cHBvcnQgdGhlIERPVFMgbWlzc2lvbiBvZiBzdGFuZGFyZHMtYmFz
ZWQgdGhyZWF0IHNpZ25hbGluZy4NCg0KZHJhZnQtZnUtZG90cy1pcGZpeC1leHRlbnNpb24tMDAg
ZG9lcyBub3QgbWVldCB0aGVzZSBjcml0ZXJpYTsgaXQgaXMgd2hvbGx5IHVuY29uY2VybmVkIHdp
dGggdGhyZWF0IHNpZ25hbGluZy4NCg0KW0ZyYW5rXTogSXQncyByZWxhdGVkIHdpdGggd2hhdCBp
bmZvcm1hdGlvbiBhYm91dCB0aHJlYXQgb3IgYXR0YWNrIGNhbiBiZSB1c2VkIGZvciBET1RTIHRo
cmVhdCBzaWduYWxpbmcuIERvIHlvdSBtZWFuIHRoZSBhdHRhY2sgdGVsZW1ldHJ5IGluZm9ybWF0
aW9uIGlzIG5vdCB0aGUgZ29hbCBvZiBET1RTPw0KDQogRnJvbSB0aGUgRE9UUyBXRyBjaGFydGVy
Og0KDQogICBBbnkgbW9kaWZpY2F0aW9uIG9mIG9yIGV4dGVuc2lvbiB0byBleGlzdGluZyBwcm90
b2NvbHMgbXVzdCBiZSBpbiBjbG9zZSBjb29yZGluYXRpb24gd2l0aCB0aGUgd29ya2luZw0KICAg
Z3JvdXBzIHJlc3BvbnNpYmxlIGZvciB0aGUgcHJvdG9jb2wgYmVpbmcgbW9kaWZpZWQsIGFuZCBt
YXkgYmUgZG9uZSBpbiB0aGlzIHdvcmtpbmcgZ3JvdXAgYWZ0ZXIgYWdyZWVtZW50DQogICB3aXRo
IGFsbCB0aGUgcmVsZXZhbnQgV0dzIGFuZCByZXNwb25zaWJsZSBBcmVhIERpcmVjdG9ycy4NCg0K
VGhlIGFib3ZlIGNyaXRlcmlhIGZyb20gdGhlIERPVFMgV0cgY2hhcnRlciBoYXZlIG5vdCBiZWVu
IGZ1bGZpbGxlZCB3aXRoIHJlZ2FyZHMgdG8gYW55IHByb3Bvc2VkIGV4dGVuc2lvbiBvZiBJUEZJ
WC4NCg0KSXQgaXMgcmVzcGVjdGZ1bGx5IHN1Z2dlc3RlZCB0byB0aGUgY2hhaXJzIHRoYXQgdGhp
cyBkcmFmdCAoYXMgaW4gaXRzIHByZXZpb3VzIGl0ZXJhdGlvbikgaXMgbW9yZSBzdWl0ZWQgZm9y
IHRoZSAoY3VycmVudGx5IENvbmNsdWRlZCkgSVBGSVggV0csIGFzIGl0IGlzIG5vdCBkaXJlY3Rs
eSByZWxhdGVkIHRvIHRoZSBwb3RlbnRpYWwgdXNlIG9mIElQRklYIGZvciB0aHJlYXQgc2lnbmFs
aW5nLCBidXQgaXMgbW9yZSBvZiBhIHByb3Bvc2VkIGdlbmVyYWwgZXh0ZW5zaW9uIG9mIElQRklY
LiAgDQoNCltGcmFua106IEZyb20gbXkgcGVyc3BlY3RpdmUsIHRoaXMgZHJhZnQgaXMgcmVsYXRl
ZCB0byB0aGUgcG90ZW50aWFsIHVzZSBvZiBJUEZJWCBmb3IgdGhlIGF0dGFjayB0ZWxlbWV0cnku
DQoNCg0KQXMgc3VjaCwgaXRzIGF1dGhvcnMgd291bGQgbW9yZSBwcm9maXRhYmx5IGRpcmVjdCB0
aGVpciBlZmZvcnRzIGluIHRoaXMgcmVnYXJkIGJ5IHBldGl0aW9uaW5nIGZvciBhIHJlb3Blbmlu
ZyBvZiB0aGUgSVBGSVggV0cuDQoNCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
DQpSb2xhbmQgRG9iYmlucyA8cmRvYmJpbnNAYXJib3IubmV0Pg0KDQpfX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXw0KRG90cyBtYWlsaW5nIGxpc3QNCkRvdHNA
aWV0Zi5vcmcNCmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vZG90cw0K


From nobody Mon Oct 19 11:19:13 2015
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 262AB1B2B4E for <dots@ietfa.amsl.com>; Mon, 19 Oct 2015 11:19:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level: 
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bkOpk7i8NVDp for <dots@ietfa.amsl.com>; Mon, 19 Oct 2015 11:19:09 -0700 (PDT)
Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96CA31B2B2B for <dots@ietf.org>; Mon, 19 Oct 2015 11:19:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3030; q=dns/txt; s=iport; t=1445278750; x=1446488350; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=ZUNZEvRu/Ac04Cn5FyCXwSv695l+paHIkqNNm98Ssxg=; b=ilN3gOo4EfoccMi4UK02okAoafN4wCAp1KaWpILQgPLtmt4rxDb+ivgx OQM3IM+0KAnVkijauSgTM3i/6wA9gXkz1k4W230Bx5lsIIDjnLsrQcVrT 7ZbqBPNxyZJguPmUhIki6ZHHrJPF7/s6aGVXjokXUlcQkyEDZrpi0wNvo 8=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D+AQBnMyVW/4MNJK1egzZUbwa+CQENgVohhX0CHIEgOBQBAQEBAQEBfwuELQEBAQQjEUMOBAIBCBEEAQEDAiMDAgICMBQBBgEBBQMCBBMIiCgNsVOSaQEBAQEBAQEBAQEBAQEBAQEBAQEBARiBIoVVhH6ENQ1SBoJjgUUFjRKJEQGFGId9gV9Ig3SWAwEfAQFChANyAYQeQoEGAQEB
X-IronPort-AV: E=Sophos;i="5.17,703,1437436800"; d="scan'208";a="199408650"
Received: from alln-core-1.cisco.com ([173.36.13.131]) by alln-iport-5.cisco.com with ESMTP; 19 Oct 2015 18:19:09 +0000
Received: from XCH-ALN-016.cisco.com (xch-aln-016.cisco.com [173.36.7.26]) by alln-core-1.cisco.com (8.14.5/8.14.5) with ESMTP id t9JIJ8LO004344 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dots@ietf.org>; Mon, 19 Oct 2015 18:19:08 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-016.cisco.com (173.36.7.26) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Mon, 19 Oct 2015 13:18:50 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1104.000; Mon, 19 Oct 2015 13:18:50 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-reddy-dots-transport-01.txt
Thread-Index: AQHRCg7D+7nDC+xk7EmfQZsiGmVPxZ5zIL6Q
Date: Mon, 19 Oct 2015 18:18:50 +0000
Message-ID: <786ec46009694999a475784750d3200f@XCH-RCD-017.cisco.com>
References: <20151019013801.1066.74990.idtracker@ietfa.amsl.com>
In-Reply-To: <20151019013801.1066.74990.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.34.22]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/0GoUPAI3rzSSQ038mIjlmYKRINo>
Subject: [Dots] FW: New Version Notification for draft-reddy-dots-transport-01.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Oct 2015 18:19:11 -0000

aHR0cHM6Ly90b29scy5pZXRmLm9yZy9odG1sL2RyYWZ0LXJlZGR5LWRvdHMtdHJhbnNwb3J0LTAx
IGV4cGxhaW5zIERPVFMgc2lnbmFsaW5nIHByb3RvY29sIGFuZCBtZWV0cyBtb3N0IG9mIHRoZSBy
ZXF1aXJlbWVudHMgZGlzY3Vzc2VkIGluICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJh
ZnQtaWV0Zi1kb3RzLXJlcXVpcmVtZW50cy0wMC4gDQoNCkNvbW1lbnRzIGFuZCBzdWdnZXN0aW9u
cyBhcmUgd2VsY29tZS4NCg0KLVRpcnUuDQoNCi0tLS0tT3JpZ2luYWwgTWVzc2FnZS0tLS0tDQpG
cm9tOiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmcgW21haWx0bzppbnRlcm5ldC1kcmFmdHNAaWV0
Zi5vcmddIA0KU2VudDogTW9uZGF5LCBPY3RvYmVyIDE5LCAyMDE1IDc6MDggQU0NClRvOiBQcmFz
aGFudGggUGF0aWwgKHByYXNwYXRpKTsgVGlydW1hbGVzd2FyIFJlZGR5ICh0aXJlZGR5KTsgVGly
dW1hbGVzd2FyIFJlZGR5ICh0aXJlZGR5KTsgRGFuIFdpbmcgKGR3aW5nKTsgTWlrZSBHZWxsZXIg
KG1nZWxsZXIpOyBNb2hhbWVkIEJvdWNhZGFpcjsgTWlrZSBHZWxsZXIgKG1nZWxsZXIpOyBQcmFz
aGFudGggUGF0aWwgKHByYXNwYXRpKTsgUm9iZXJ0IE1vc2tvd2l0ejsgUm9iZXJ0IE1vc2tvd2l0
ejsgTW9oYW1lZCBCb3VjYWRhaXI7IERhbiBXaW5nIChkd2luZykNClN1YmplY3Q6IE5ldyBWZXJz
aW9uIE5vdGlmaWNhdGlvbiBmb3IgZHJhZnQtcmVkZHktZG90cy10cmFuc3BvcnQtMDEudHh0DQoN
Cg0KQSBuZXcgdmVyc2lvbiBvZiBJLUQsIGRyYWZ0LXJlZGR5LWRvdHMtdHJhbnNwb3J0LTAxLnR4
dA0KaGFzIGJlZW4gc3VjY2Vzc2Z1bGx5IHN1Ym1pdHRlZCBieSBUaXJ1bWFsZXN3YXIgUmVkZHkg
YW5kIHBvc3RlZCB0byB0aGUNCklFVEYgcmVwb3NpdG9yeS4NCg0KTmFtZToJCWRyYWZ0LXJlZGR5
LWRvdHMtdHJhbnNwb3J0DQpSZXZpc2lvbjoJMDENClRpdGxlOgkJQ28tb3BlcmF0aXZlIEREb1Mg
TWl0aWdhdGlvbg0KRG9jdW1lbnQgZGF0ZToJMjAxNS0xMC0xOA0KR3JvdXA6CQlJbmRpdmlkdWFs
IFN1Ym1pc3Npb24NClBhZ2VzOgkJMTMNClVSTDogICAgICAgICAgICBodHRwczovL3d3dy5pZXRm
Lm9yZy9pbnRlcm5ldC1kcmFmdHMvZHJhZnQtcmVkZHktZG90cy10cmFuc3BvcnQtMDEudHh0DQpT
dGF0dXM6ICAgICAgICAgaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtcmVk
ZHktZG90cy10cmFuc3BvcnQvDQpIdG1saXplZDogICAgICAgaHR0cHM6Ly90b29scy5pZXRmLm9y
Zy9odG1sL2RyYWZ0LXJlZGR5LWRvdHMtdHJhbnNwb3J0LTAxDQpEaWZmOiAgICAgICAgICAgaHR0
cHM6Ly93d3cuaWV0Zi5vcmcvcmZjZGlmZj91cmwyPWRyYWZ0LXJlZGR5LWRvdHMtdHJhbnNwb3J0
LTAxDQoNCkFic3RyYWN0Og0KICAgVGhpcyBkb2N1bWVudCBkaXNjdXNzZXMgbWVjaGFuaXNtcyB0
aGF0IGEgRE9UUyBjbGllbnQgY2FuIHVzZSwgd2hlbg0KICAgaXQgZGV0ZWN0cyBhIHBvdGVudGlh
bCBEaXN0cmlidXRlZCBEZW5pYWwtb2YtU2VydmljZSAoRERvUykgYXR0YWNrLA0KICAgdG8gc2ln
bmFsIHRoYXQgdGhlIERPVFMgY2xpZW50IGlzIHVuZGVyIGFuIGF0dGFjayBvciByZXF1ZXN0IGFu
DQogICB1cHN0cmVhbSBET1RTIHNlcnZlciB0byBwZXJmb3JtIGluYm91bmQgZmlsdGVyaW5nIGlu
IGl0cyBpbmdyZXNzDQogICByb3V0ZXJzIGZvciB0cmFmZmljIHRoYXQgdGhlIERPVFMgY2xpZW50
IHdpc2hlcyB0byBkcm9wLiAgVGhlIERPVFMNCiAgIHNlcnZlciBjYW4gdGhlbiB1bmRlcnRha2Ug
YXBwcm9wcmlhdGUgYWN0aW9ucyAoaW5jbHVkaW5nLCBibGFja2hvbGUsDQogICBkcm9wLCByYXRl
LWxpbWl0LCBvciBhZGQgdG8gd2F0Y2ggbGlzdCkgb24gdGhlIHN1c3BlY3QgdHJhZmZpYyB0byB0
aGUNCiAgIERPVFMgY2xpZW50LCB0aHVzIHJlZHVjaW5nIHRoZSBlZmZlY3RpdmVuZXNzIG9mIHRo
ZSBhdHRhY2suDQoNCiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCg0KDQpQbGVhc2Ugbm90ZSB0
aGF0IGl0IG1heSB0YWtlIGEgY291cGxlIG9mIG1pbnV0ZXMgZnJvbSB0aGUgdGltZSBvZiBzdWJt
aXNzaW9uDQp1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQgZGlmZiBhcmUgYXZhaWxhYmxl
IGF0IHRvb2xzLmlldGYub3JnLg0KDQpUaGUgSUVURiBTZWNyZXRhcmlhdA0KDQo=


From nobody Tue Oct 20 03:30:34 2015
Return-Path: <daniel.migault@ericsson.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E6BE91B3265 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 03:30:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ShGzpL4a7KP9 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 03:30:32 -0700 (PDT)
Received: from usevmg21.ericsson.net (usevmg21.ericsson.net [198.24.6.65]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 471351A87C1 for <dots@ietf.org>; Tue, 20 Oct 2015 03:30:32 -0700 (PDT)
X-AuditID: c6180641-f792c6d00000686a-c4-5625ab1e2989
Received: from EUSAAHC002.ericsson.se (Unknown_Domain [147.117.188.78]) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id 08.65.26730.E1BA5265; Tue, 20 Oct 2015 04:46:54 +0200 (CEST)
Received: from EUSAAMB107.ericsson.se ([147.117.188.124]) by EUSAAHC002.ericsson.se ([147.117.188.78]) with mapi id 14.03.0248.002; Tue, 20 Oct 2015 06:30:30 -0400
From: Daniel Migault <daniel.migault@ericsson.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-dots-use-cases-00.txt
Thread-Index: AQHRCoplE8B6m4yxfE2D+tkI/8+xXZ50LsnA
Date: Tue, 20 Oct 2015 10:30:30 +0000
Message-ID: <2DD56D786E600F45AC6BDE7DA4E8A8C11217B7F1@eusaamb107.ericsson.se>
References: <20151019162244.18886.799.idtracker@ietfa.amsl.com>
In-Reply-To: <20151019162244.18886.799.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [147.117.188.12]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmplkeLIzCtJLcpLzFFi42KZXLrHT1dutWqYwaVvMhZr3xxhtfjTdYDZ ou3TUSaLtwvDLS7tPMFk0fKthc2BzWPL5V52j+aFE9k8Wo68ZfVYsuQnk8e73tVMHrs2N7AF sEVx2aSk5mSWpRbp2yVwZUxs8yk4J1zx+9Yh1gbGHuEuRk4OCQETiakrdzFB2GISF+6tZ+ti 5OIQEjjKKHHrzHEWCGc5o8TL40dYQKrYBIwk2g71s4PYIgLKEjub7jKCFDELXGCUOP4EokhY wEvi4uQ2Nogib4n9G25C2UYSazZ9BathEVCVeNw3A6iZg4NXwFdi76ZKkLCQgL3EtdaPYPM5 BRwkzj+fygpiMwJd9/3UGrBLmQXEJW49mQ91tYDEkj3nmSFsUYmXj/+xQthKEnNeX2MGGc8s oCmxfpc+RKuixJTuh2DjeQUEJU7OfMIygVFsFpKpsxA6ZiHpmIWkYwEjyypGjtLi1LLcdCPD TYzAeDsmwea4g3HBJ8tDjAIcjEo8vAnfVcKEWBPLiitzDzFKc7AoifPOm3E/VEggPbEkNTs1 tSC1KL6oNCe1+BAjEwenVAOjy5SjhtsvCmvHznMJ+3inf+enZV/zZjTwugcpzAnd8PR3SfNC zydSUVL7LbT4HpktXD5bqN4h/+q2tc/vLmD+xRWiEHbk1t4VwfJf3H/EcnRPEDR/u134yP+f NmESwe7fn7KeedZxaccLTj15i1PvWG9+vmsXYlQrer7rNKN9/MVH+f6HJZy4lFiKMxINtZiL ihMB9Fshd5gCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/uUurL3mUB5UIuVS6wgNxMeui27Q>
Cc: Roland Dobbins <rdobbins@arbor.net>, Stephane Fouant <stefan.fouant@corero.com>, Liang Xia <frank.xialiang@huawei.com>, Robert Moskowitz <rgm@labs.htt-consult.com>, Nik Teague <nteague@verisign.com>
Subject: Re: [Dots] New Version Notification for draft-ietf-dots-use-cases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 10:30:34 -0000

SGksIA0KDQpQbGVhc2UgZmluZCB0aGUgdXNlIGNhc2VzIGRvY3VtZW50LiBGZWVsIGZyZWUgdG8g
Y29tbWVudCBvbiB0aGUgTUwuIFdlIHdpbGwgYmUgaGFwcHkgdG8gYWRkcmVzcyB0aGVtIG9uIHRo
ZSBNTCBvciBkaXNjdXNzIHRoZW0gZnVydGhlciBhdCB0aGUgSUVURjk0Lg0KDQpCUiwgDQpEYW5p
ZWwgDQoNCg0KLS0tLS1PcmlnaW5hbCBNZXNzYWdlLS0tLS0NCkZyb206IGludGVybmV0LWRyYWZ0
c0BpZXRmLm9yZyBbbWFpbHRvOmludGVybmV0LWRyYWZ0c0BpZXRmLm9yZ10gDQpTZW50OiBNb25k
YXksIE9jdG9iZXIgMTksIDIwMTUgNToyMyBQTQ0KVG86IFN0ZXBoYW5lIEZvdWFudDsgTmlrIFRl
YWd1ZTsgTmlrIFRlYWd1ZTsgTGlhbmcgWGlhOyBSb2JlcnQgTW9za293aXR6OyBSb2JlcnQgTW9z
a293aXR6OyBSb2xhbmQgRG9iYmluczsgU3RlcGhhbmUgRm91YW50OyBEYW5pZWwgTWlnYXVsdDsg
Um9sYW5kIERvYmJpbnM7IERhbmllbCBNaWdhdWx0OyBMaWFuZyBYaWENClN1YmplY3Q6IE5ldyBW
ZXJzaW9uIE5vdGlmaWNhdGlvbiBmb3IgZHJhZnQtaWV0Zi1kb3RzLXVzZS1jYXNlcy0wMC50eHQN
Cg0KDQpBIG5ldyB2ZXJzaW9uIG9mIEktRCwgZHJhZnQtaWV0Zi1kb3RzLXVzZS1jYXNlcy0wMC50
eHQgaGFzIGJlZW4gc3VjY2Vzc2Z1bGx5IHN1Ym1pdHRlZCBieSBEYW5pZWwgTWlnYXVsdCBhbmQg
cG9zdGVkIHRvIHRoZSBJRVRGIHJlcG9zaXRvcnkuDQoNCk5hbWU6CQlkcmFmdC1pZXRmLWRvdHMt
dXNlLWNhc2VzDQpSZXZpc2lvbjoJMDANClRpdGxlOgkJVXNlIGNhc2VzIGZvciBERG9TIE9wZW4g
VGhyZWF0IFNpZ25hbGluZw0KRG9jdW1lbnQgZGF0ZToJMjAxNS0xMC0xOQ0KR3JvdXA6CQlkb3Rz
DQpQYWdlczoJCTIyDQpVUkw6ICAgICAgICAgICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvaW50ZXJu
ZXQtZHJhZnRzL2RyYWZ0LWlldGYtZG90cy11c2UtY2FzZXMtMDAudHh0DQpTdGF0dXM6ICAgICAg
ICAgaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtaWV0Zi1kb3RzLXVzZS1j
YXNlcy8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQt
aWV0Zi1kb3RzLXVzZS1jYXNlcy0wMA0KDQoNCkFic3RyYWN0Og0KICAgVGhpcyBkb2N1bWVudCBk
ZWxpbmVhdGVzIHByaW5jaXBhbCBhbmQgYW5jaWxsYXJ5IHVzZSBjYXNlcyBmb3IgRERvUw0KICAg
T3BlbiBUaHJlYXQgU2lnbmFsaW5nIChET1RTKSwgYSBjb21tdW5pY2F0aW9ucyBwcm90b2NvbCBp
bnRlbmRlZCB0bw0KICAgZmFjaWxpdGF0ZSB0aGUgcHJvZ3JhbW1hdGljLCBjb29yZGluYXRlZCBt
aXRpZ2F0aW9uIG9mIERpc3RyaWJ1dGVkDQogICBEZW5pYWwgb2YgU2VydmljZSAoRERvUykgYXR0
YWNrcyB2aWEgYSBzdGFuZGFyZHMtYmFzZWQgbWVjaGFuaXNtLg0KICAgRE9UUyBpcyBwdXJwb3Nl
bHkgZGVzaWduZWQgdG8gc3VwcG9ydCByZXF1ZXN0cyBmb3IgRERvUyBtaXRpZ2F0aW9uDQogICBz
ZXJ2aWNlcyBhbmQgc3RhdHVzIHVwZGF0ZXMgYWNyb3NzIGludGVyLW9yZ2FuaXphdGlvbmFsDQog
ICBhZG1pbmlzdHJhdGl2ZSBib3VuZGFyaWVzLg0KDQogICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
DQoNCg0KUGxlYXNlIG5vdGUgdGhhdCBpdCBtYXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZy
b20gdGhlIHRpbWUgb2Ygc3VibWlzc2lvbiB1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQg
ZGlmZiBhcmUgYXZhaWxhYmxlIGF0IHRvb2xzLmlldGYub3JnLg0KDQpUaGUgSUVURiBTZWNyZXRh
cmlhdA0KDQo=


From nobody Tue Oct 20 03:41:00 2015
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4F7FC1A87F1 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 03:40:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level: 
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xCuNKOgV0rVw for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 03:40:57 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BD0031A87EF for <dots@ietf.org>; Tue, 20 Oct 2015 03:40:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2012; q=dns/txt; s=iport; t=1445337657; x=1446547257; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=SCCbFZk3ePqq+EeOKuVOZHRnH7te69q5JxFSOqqUzik=; b=ag+NkYFhP2XFR7qIoBMIQUK1Ch+ufk8gOzvrsrsCjlt6khjx+yRavtYM ldSsrtelLzXncJ3gVKtbw/IqsaLUrthUPjLwziR8N6M89hwGtClEefO06 zpRl2vx6CIQSmKwuk+/BO7L8+07upyHm6v/TTVj1CO8AbO0s4o/jBjaNC s=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D5AQBiGSZW/4wNJK1egzZUbwa+FAENgVojhXsCHIEfOBQBAQEBAQEBfwuELQEBAQQjEUMOBAIBCBEEAQEDAiMDAgICMBQBBgEBBQMCBBMIiCgNsHGTFAEBAQEBAQEBAQEBAQEBAQEBAQEBARiBIoVVhH6EciIGgmOBRQWNEokSAYUYh3+BX0iDd5YJAR8BAUKEA3IBhGCBBgEBAQ
X-IronPort-AV: E=Sophos;i="5.17,707,1437436800"; d="scan'208";a="199808090"
Received: from alln-core-7.cisco.com ([173.36.13.140]) by alln-iport-8.cisco.com with ESMTP; 20 Oct 2015 10:40:57 +0000
Received: from XCH-RCD-017.cisco.com (xch-rcd-017.cisco.com [173.37.102.27]) by alln-core-7.cisco.com (8.14.5/8.14.5) with ESMTP id t9KAevQD000681 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dots@ietf.org>; Tue, 20 Oct 2015 10:40:57 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-RCD-017.cisco.com (173.37.102.27) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Tue, 20 Oct 2015 05:40:38 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1104.000; Tue, 20 Oct 2015 05:40:38 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-dots-requirements-00.txt
Thread-Index: AQHRCpNmgR/o3RGf+k69woBbrWOg+p50MV/A
Date: Tue, 20 Oct 2015 10:40:38 +0000
Message-ID: <e53b6364e4ee46788217a8ad84bbe49d@XCH-RCD-017.cisco.com>
References: <20151019172722.23547.75886.idtracker@ietfa.amsl.com>
In-Reply-To: <20151019172722.23547.75886.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [173.39.65.7]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/Vo3nRJnXT4yALlgoi9x5KHjx0fo>
Subject: [Dots] FW: New Version Notification for draft-ietf-dots-requirements-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 10:40:59 -0000

aHR0cHM6Ly90b29scy5pZXRmLm9yZy9odG1sL2RyYWZ0LWlldGYtZG90cy1yZXF1aXJlbWVudHMt
MDAgZGlzY3Vzc2VzIHJlcXVpcmVtZW50cyBmb3IgdGhlIERPVFMgc2lnbmFsaW5nIHByb3RvY29s
cy4gDQoNCkNvbW1lbnRzIGFuZCBzdWdnZXN0aW9ucyBhcmUgd2VsY29tZS4NCg0KLVRpcnUNCg0K
LS0tLS1PcmlnaW5hbCBNZXNzYWdlLS0tLS0NCkZyb206IGludGVybmV0LWRyYWZ0c0BpZXRmLm9y
ZyBbbWFpbHRvOmludGVybmV0LWRyYWZ0c0BpZXRmLm9yZ10gDQpTZW50OiBNb25kYXksIE9jdG9i
ZXIgMTksIDIwMTUgMTA6NTcgUE0NClRvOiBBbmRyZXcgTW9ydGVuc2VuOyBUaXJ1bWFsZXN3YXIg
UmVkZHkgKHRpcmVkZHkpOyBSb2JlcnQgTW9za293aXR6DQpTdWJqZWN0OiBOZXcgVmVyc2lvbiBO
b3RpZmljYXRpb24gZm9yIGRyYWZ0LWlldGYtZG90cy1yZXF1aXJlbWVudHMtMDAudHh0DQoNCg0K
QSBuZXcgdmVyc2lvbiBvZiBJLUQsIGRyYWZ0LWlldGYtZG90cy1yZXF1aXJlbWVudHMtMDAudHh0
DQpoYXMgYmVlbiBzdWNjZXNzZnVsbHkgc3VibWl0dGVkIGJ5IEFuZHJldyBNb3J0ZW5zZW4gYW5k
IHBvc3RlZCB0byB0aGUgSUVURiByZXBvc2l0b3J5Lg0KDQpOYW1lOgkJZHJhZnQtaWV0Zi1kb3Rz
LXJlcXVpcmVtZW50cw0KUmV2aXNpb246CTAwDQpUaXRsZToJCUREb1MgT3BlbiBUaHJlYXQgU2ln
bmFsaW5nIFJlcXVpcmVtZW50cw0KRG9jdW1lbnQgZGF0ZToJMjAxNS0xMC0xOQ0KR3JvdXA6CQlk
b3RzDQpQYWdlczoJCTEyDQpVUkw6ICAgICAgICAgICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvaW50
ZXJuZXQtZHJhZnRzL2RyYWZ0LWlldGYtZG90cy1yZXF1aXJlbWVudHMtMDAudHh0DQpTdGF0dXM6
ICAgICAgICAgaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtaWV0Zi1kb3Rz
LXJlcXVpcmVtZW50cy8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0
bWwvZHJhZnQtaWV0Zi1kb3RzLXJlcXVpcmVtZW50cy0wMA0KDQoNCkFic3RyYWN0Og0KICAgVGhp
cyBkb2N1bWVudCBkZWZpbmVzIHRoZSByZXF1aXJlbWVudHMgZm9yIHRoZSBERG9TIE9wZW4gVGhy
ZWF0DQogICBTaWduYWxpbmcgKERPVFMpIHByb3RvY29scyBjb29yZGluYXRpbmcgYXR0YWNrIHJl
c3BvbnNlIGFnYWluc3QNCiAgIERpc3RyaWJ1dGVkIERlbmlhbCBvZiBTZXJ2aWNlIChERG9TKSBh
dHRhY2tzLg0KDQogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgDQoNCg0KUGxlYXNlIG5vdGUgdGhh
dCBpdCBtYXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZyb20gdGhlIHRpbWUgb2Ygc3VibWlz
c2lvbiB1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQgZGlmZiBhcmUgYXZhaWxhYmxlIGF0
IHRvb2xzLmlldGYub3JnLg0KDQpUaGUgSUVURiBTZWNyZXRhcmlhdA0KDQo=


From nobody Tue Oct 20 05:05:04 2015
Return-Path: <rgm-sec@htt-consult.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 586711B33A6 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 05:05:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rPgnZzHRstRd for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 05:04:56 -0700 (PDT)
Received: from z9m9z.htt-consult.com (z9m9z.htt-consult.com [50.253.254.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F35A61B3395 for <dots@ietf.org>; Tue, 20 Oct 2015 05:04:51 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by z9m9z.htt-consult.com (Postfix) with ESMTP id 7D6375FA37; Tue, 20 Oct 2015 08:04:49 -0400 (EDT)
X-Virus-Scanned: amavisd-new at htt-consult.com
Received: from z9m9z.htt-consult.com ([127.0.0.1]) by localhost (z9m9z.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with LMTP id l5CHbGjNahf0; Tue, 20 Oct 2015 08:04:34 -0400 (EDT)
Received: from lx120e.htt-consult.com (unknown [192.168.160.20]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by z9m9z.htt-consult.com (Postfix) with ESMTPSA id 561275FA1B; Tue, 20 Oct 2015 08:04:33 -0400 (EDT)
To: Roland Dobbins <rdobbins@arbor.net>, dots <dots@ietf.org>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net>
From: Robert Moskowitz <rgm-sec@htt-consult.com>
Message-ID: <56262DCE.1070801@htt-consult.com>
Date: Tue, 20 Oct 2015 08:04:30 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0
MIME-Version: 1.0
In-Reply-To: <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/_Gj8ibma3LG5UU9MNQ0u3UxnajE>
Cc: "Roman D. Danyliw" <rdd@cert.org>, Tobias Gondrom <tobias.gondrom@gondrom.org>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 12:05:01 -0000

Roland,  If IPFIX meets the requirements for a DOTS transport, then it 
is within scope.

Actually, our next major work item needs to be developing a data model 
and registry of the DOTS signal messages.  This needs to be independent 
of the transport

If JSON over SRTP is the best fit for DOTS transport then it would be in 
scope.  We need a transport, and we have the requirements.  Or at least 
the 00 cut for the requirements.  Let's take a reasonable view of what 
we have out there that can meet those requirements and support a concise 
data representation.

On 10/18/2015 11:18 PM, Roland Dobbins wrote:
>
> On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:
>
>> May I request for a 5 or 10 minutes time slot for presenting the 
>> following draft, as an input for the discussion about attack 
>> telemetry information?
>
> From the DOTS WG charter:
>
>   The WG will, where appropriate, reuse or extend existing standard
>   protocols and mechanisms (for example, IPFIX and its associated
>   templating and extension mechanisms).
>
> This language in the DOTS WG charter is not intended to suggest a 
> general extension of any existing standards such as IPFIX; rather, it 
> is intended to note that should an existing standard may be desirable 
> for use within the context of threat signaling, the DOTS WG may 
> request an extension of said standard to support the DOTS mission of 
> standards-based threat signaling.
>
> draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is 
> wholly unconcerned with threat signaling.
>
> From the DOTS WG charter:
>
>   Any modification of or extension to existing protocols must be in 
> close coordination with the working
>   groups responsible for the protocol being modified, and may be done 
> in this working group after agreement
>   with all the relevant WGs and responsible Area Directors.
>
> The above criteria from the DOTS WG charter have not been fulfilled 
> with regards to any proposed extension of IPFIX.
>
> It is respectfully suggested to the chairs that this draft (as in its 
> previous iteration) is more suited for the (currently Concluded) IPFIX 
> WG, as it is not directly related to the potential use of IPFIX for 
> threat signaling, but is more of a proposed general extension of 
> IPFIX.  As such, its authors would more profitably direct their 
> efforts in this regard by petitioning for a reopening of the IPFIX WG.
>
> -----------------------------------
> Roland Dobbins <rdobbins@arbor.net>
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots
>


From nobody Tue Oct 20 10:48:14 2015
Return-Path: <amortensen@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BD331A8881 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 10:48:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mPPqWhsNSimN for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 10:48:11 -0700 (PDT)
Received: from mail-ig0-x229.google.com (mail-ig0-x229.google.com [IPv6:2607:f8b0:4001:c05::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 43BDC1ACE15 for <dots@ietf.org>; Tue, 20 Oct 2015 10:46:04 -0700 (PDT)
Received: by igbhv6 with SMTP id hv6so20073541igb.0 for <dots@ietf.org>; Tue, 20 Oct 2015 10:46:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=Wf6uHr8BKL4n1JhdZLf++g8uxUvB/tqhClU8q4Yl0OI=; b=kokSli+eBBxHQYcpgbrDSrcSvnCB7U+heWKtFF93jDKygcVlkEg+dLuf05oyl1MwGR KG3V4/9DOEEaTodQ7lW02o3hrrGqZBg1OurqWSqvkqyCgJtLS/6Txr70cl7JjGsY4z4y Pr9rf2s3K5b10xw47cVBtrF5xrerRI0XRfmS4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=Wf6uHr8BKL4n1JhdZLf++g8uxUvB/tqhClU8q4Yl0OI=; b=VAIL0wxWTKC9LoF1fbhHEukURY67jleWjkyixprAEJpLTjBtRbdQtmVm0Ri6NC0fGb Kcb9tYL92uHtD/7AeywhxoPtOoASFi8LNoCOd4Eni22yniiIMcC0k4veWltH+U9v5LDk xxtKyBVcUEWi7uAvU6HOZPsFK+qvt8XbdCXwC+pAJUfO17o7NBCUML31XOuRN0sK4iOO vDzL5FplDw3M+fcHV2iNBdLBWMEGBL6IMxfpbHB+Q83gyRLmu5/yR0zl5ff9oaBS4bnO TxE705vNaEUmf76hPi2hK6MD/7VMrD+p0FXSQVeJ0y5EVnz2nZszvuTqxJcPhvAitk/Q /pQg==
X-Gm-Message-State: ALoCoQk7o+wmpszPklL4yOM6VZalhmR5lG+/2sKaul8U5D1Lm7/tryA69MZBMc0aKueflvD8k5Fr
X-Received: by 10.50.134.37 with SMTP id ph5mr5651166igb.88.1445363163606; Tue, 20 Oct 2015 10:46:03 -0700 (PDT)
Received: from desktop-10-16.aa.arbor.net ([216.130.192.3]) by smtp.gmail.com with ESMTPSA id e20sm1886997ioe.42.2015.10.20.10.46.02 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 20 Oct 2015 10:46:02 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Andrew Mortensen <amortensen@arbor.net>
In-Reply-To: <56262DCE.1070801@htt-consult.com>
Date: Tue, 20 Oct 2015 13:46:03 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <06E807DB-27F9-44FC-BAD4-AB55BC64B5CF@arbor.net>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <56262DCE.1070801@htt-consult.com>
To: Robert Moskowitz <rgm-sec@htt-consult.com>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/a8eF9tqdcSSEUOei3kxmzScFmE4>
Cc: Roland Dobbins <rdobbins@arbor.net>, "Roman D. Danyliw" <rdd@cert.org>, Tobias Gondrom <tobias.gondrom@gondrom.org>, dots <dots@ietf.org>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 17:48:13 -0000

> On Oct 20, 2015, at 8:04 AM, Robert Moskowitz =
<rgm-sec@htt-consult.com> wrote:
>=20
> Roland,  If IPFIX meets the requirements for a DOTS transport, then it =
is within scope.

That=E2=80=99s true, but draft-fu-dots-ipfix-extension refers to DOTS =
only twice: once as the WG name in the header, and once in the draft =
name. The rest of the text defines IPFIX extensions that purport to =
enhance DDoS detection via flow collection, not anything related to DOTS =
signaling. These extensions may indeed be useful additions to the IPFIX =
specification=E2=80=94I haven=E2=80=99t seen any evidence one way or the =
other=E2=80=94but this draft=E2=80=99s relationship to DOTS's goals is =
not clear to me. Nothing in the draft seems to position it as a solution =
or supplement for DOTS.

> Actually, our next major work item needs to be developing a data model =
and registry of the DOTS signal messages.  This needs to be independent =
of the transport
>=20
> If JSON over SRTP is the best fit for DOTS transport then it would be =
in scope.  We need a transport, and we have the requirements.  Or at =
least the 00 cut for the requirements.  Let's take a reasonable view of =
what we have out there that can meet those requirements and support a =
concise data representation.

Agreed, I=E2=80=99m strongly in favor of continuing this discussion. =
I=E2=80=99d like to see some feedback on the requirements and use cases =
first, though.

andrew




>=20
> On 10/18/2015 11:18 PM, Roland Dobbins wrote:
>>=20
>> On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:
>>=20
>>> May I request for a 5 or 10 minutes time slot for presenting the =
following draft, as an input for the discussion about attack telemetry =
information?
>>=20
>> =46rom the DOTS WG charter:
>>=20
>>  The WG will, where appropriate, reuse or extend existing standard
>>  protocols and mechanisms (for example, IPFIX and its associated
>>  templating and extension mechanisms).
>>=20
>> This language in the DOTS WG charter is not intended to suggest a =
general extension of any existing standards such as IPFIX; rather, it is =
intended to note that should an existing standard may be desirable for =
use within the context of threat signaling, the DOTS WG may request an =
extension of said standard to support the DOTS mission of =
standards-based threat signaling.
>>=20
>> draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is =
wholly unconcerned with threat signaling.
>>=20
>> =46rom the DOTS WG charter:
>>=20
>>  Any modification of or extension to existing protocols must be in =
close coordination with the working
>>  groups responsible for the protocol being modified, and may be done =
in this working group after agreement
>>  with all the relevant WGs and responsible Area Directors.
>>=20
>> The above criteria from the DOTS WG charter have not been fulfilled =
with regards to any proposed extension of IPFIX.
>>=20
>> It is respectfully suggested to the chairs that this draft (as in its =
previous iteration) is more suited for the (currently Concluded) IPFIX =
WG, as it is not directly related to the potential use of IPFIX for =
threat signaling, but is more of a proposed general extension of IPFIX.  =
As such, its authors would more profitably direct their efforts in this =
regard by petitioning for a reopening of the IPFIX WG.
>>=20
>> -----------------------------------
>> Roland Dobbins <rdobbins@arbor.net>
>>=20
>> _______________________________________________
>> Dots mailing list
>> Dots@ietf.org
>> https://www.ietf.org/mailman/listinfo/dots
>>=20
>=20
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


From nobody Tue Oct 20 10:51:01 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B92D61A8857 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 10:50:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tY5RlZMlNHtJ for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 10:50:58 -0700 (PDT)
Received: from mail-pa0-x22a.google.com (mail-pa0-x22a.google.com [IPv6:2607:f8b0:400e:c03::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B7A41A8856 for <dots@ietf.org>; Tue, 20 Oct 2015 10:50:58 -0700 (PDT)
Received: by pasz6 with SMTP id z6so27746560pas.2 for <dots@ietf.org>; Tue, 20 Oct 2015 10:50:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=H0RyhDTOysfB0w1Ok0c58CjLRImMtM5PVvHfGXLDCZA=; b=QbQckrmXkVUSiH6XcisluSEVJUP5v/Y44z01LfYGAFtLaHAfp5a05s6jh5CbkYwZKp +j0Z/lm27fBbelqe2nu2Bw0AtUY6RofunT9F11EULwEHcxQbAPFHd8F3snnmPcTYTB04 pUBXS8PV7/VvE+lEt9A6X/Hny6pwqkxLo6nCY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=H0RyhDTOysfB0w1Ok0c58CjLRImMtM5PVvHfGXLDCZA=; b=eujTTtqrEOd4c8mPgYF8BMDuRSNvRNS7xa70FI+LSR17Lhx8Wks2YlcCjZvt4IsVLN wZSGGDxv4QFrLalDTeXSiWgLp5nCzIwMOEpXlS9FRPH5qjn6V6YkktkQTMsVONrpkaXI auNnunSeTU/PA/pbMKizd3Wj8CnvfWHMm/XUQDGPedS2QQeX4QqFRs0glOUBpMmy7+1v rWVz0Q9cB99paI41Irmh4exNLsd2xV4KUNNIjVgX66ULQj4UD05vXaXbuyEWzIt8XOVm gzzJauS3p7ruOD+uci8Too6+c/r3jqrlOd00j93b8sc6pUOcFJ+y9plIe4sVcd1Ge5qY fW4Q==
X-Gm-Message-State: ALoCoQnp+c6deCt3INZ4Squ7X8bS+IT9Mm49VQ0VVNeO5GD+PRtntb2jcYFCMvTNdsREqZuynNVz
X-Received: by 10.68.216.135 with SMTP id oq7mr5350828pbc.9.1445363458181; Tue, 20 Oct 2015 10:50:58 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id ve8sm4877593pbc.48.2015.10.20.10.50.56 for <dots@ietf.org> (version=TLSv1 cipher=RC4-SHA bits=128/128); Tue, 20 Oct 2015 10:50:57 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots <dots@ietf.org>
Date: Wed, 21 Oct 2015 00:50:53 +0700
Message-ID: <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net>
In-Reply-To: <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/WKXo8ZDDlKqEcC1VnS65Cz8PbTY>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 17:50:59 -0000

On 19 Oct 2015, at 10:33, Xialiang (Frank) wrote:

> [Frank]: It's related with what information about threat or attack can 
> be used for DOTS threat signaling.
> Do you mean the attack telemetry information is not the goal of DOTS?

Correct.  This is the DDoS Open Threat Signaling WG, not the IPFIX WG.

> [Frank]: From my perspective, this draft is related to the potential 
> use of IPFIX for the attack telemetry.

Which is not within the scope of this WG.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Tue Oct 20 11:05:02 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4ECB31A8A54 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 11:04:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id znK-B5_t4Lou for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 11:04:52 -0700 (PDT)
Received: from mail-pa0-x22b.google.com (mail-pa0-x22b.google.com [IPv6:2607:f8b0:400e:c03::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D2D11A8A43 for <dots@ietf.org>; Tue, 20 Oct 2015 11:04:52 -0700 (PDT)
Received: by pabrc13 with SMTP id rc13so28010264pab.0 for <dots@ietf.org>; Tue, 20 Oct 2015 11:04:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-type; bh=+eqk/E0n50ObhKNMlvDceTc3slqj9dkC+mbEGN6XliY=; b=YaC1hotjFmvaqLnbqrzs/ZCj2S8GooOQh/38Sbxrpt0WEPbKI2KjaXZYVcMBmxLXqm lDliiaPSLUoWg7llmU+GD1xfiv/6U2VPDcham8xX9cMeSrOkmQHtrEZK5W7802t+02KS IWSLpOOfUDsdEJyIxHVOIpPrIDW7YRbjIh754=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=+eqk/E0n50ObhKNMlvDceTc3slqj9dkC+mbEGN6XliY=; b=cu++gzwEzNBXTH3KH4pdNUOLC/ZUDS9y2bV7Y1iKC+RcBPvDboMJne/sqLm19qu2fv v+ZI2DUFClFMrKyMlWsI+eQTaS7tBUuKmFn9w7KVd+11HDJ6PUvVOF92sKZNB4kXGrNx BByidULug+/wrTQOP7Bp0FB38zP8xhL/61e93SXiWKx8QjH+4btXpIk8Rv96Yb4l4o1f f4awn9MaPqEEK7Tk57VkZ8UgNlYtoXUmG4B7IcTNASKlRxZP8IWCX2SRJ0aQuEPWbWCn OwiE/PSM5jC41eMY+DOSG98uXpdgL0MXxRoV5MjegIKtcxo4h6bEtfjGHMcSmyN3mmfh GFSg==
X-Gm-Message-State: ALoCoQlS94pK3YQxduYoJtRXSWXaIt/KN1onsPtAvt7W1JoYMiExA+xooscidqp5Vfc5pVwfuJtB
X-Received: by 10.68.180.131 with SMTP id do3mr5362793pbc.133.1445364291872; Tue, 20 Oct 2015 11:04:51 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id hq8sm4922469pad.35.2015.10.20.11.04.49 (version=TLSv1 cipher=RC4-SHA bits=128/128); Tue, 20 Oct 2015 11:04:51 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots <dots@ietf.org>
Date: Wed, 21 Oct 2015 01:04:46 +0700
Message-ID: <5B392BBC-7D27-4898-9649-86DDF7C00826@arbor.net>
In-Reply-To: <56262DCE.1070801@htt-consult.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <56262DCE.1070801@htt-consult.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/KgvKdw7SR82RU_JajZcqhOYXmBQ>
Cc: "Roman D. Danyliw" <rdd@cert.org>, Tobias Gondrom <tobias.gondrom@gondrom.org>, Robert Moskowitz <rgm-sec@htt-consult.com>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Oct 2015 18:04:55 -0000

On 20 Oct 2015, at 19:04, Robert Moskowitz wrote:

> Roland,  If IPFIX meets the requirements for a DOTS transport, then it 
> is within scope.

Concur - that's the very specific meaning of the verbiage to the charter 
which refers to adopting/extending existing standards such as IPFIX, if 
they're deemed useful for fulfilling the mission of DOTS, which is 
threat signaling.

As Andrew Mortensen indicated, draft-fu-dots-ipfix-extension-00 has 
nothing to do with threat signaling - it has to do with the parts of 
draft-ietf-dots-requirements-00 described as 'the mechanism by which 
this process takes place is beyond the scope of this document'.

 From the DOTS perspective, draft-fu-dots-ipfix-extension-00 is 
behind-the-curtains stuff which has no direct applicability to threat 
signaling, and is thus outside the scope of the DOTS WG.  It falls under 
the rubric of the IPFIX WG, which is currently in Concluded status.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Tue Oct 20 23:08:03 2015
Return-Path: <kaname@nttv6.jp>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 06A361A8F3B for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 23:08:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.598
X-Spam-Level: 
X-Spam-Status: No, score=0.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265, HTML_MESSAGE=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ngsY2fVoL4g9 for <dots@ietfa.amsl.com>; Tue, 20 Oct 2015 23:08:01 -0700 (PDT)
Received: from guri.nttv6.jp (guri.nttv6.jp [IPv6:2402:c800:ff06:a::4]) by ietfa.amsl.com (Postfix) with ESMTP id BBF141B35C6 for <dots@ietf.org>; Tue, 20 Oct 2015 23:08:00 -0700 (PDT)
Received: from z.nttv6.jp (z.nttv6.jp [IPv6:2402:c800:ff06:6::f]) by guri.nttv6.jp (NTTv6MTA) with ESMTP id E1A154E8A5 for <dots@ietf.org>; Wed, 21 Oct 2015 15:07:59 +0900 (JST)
Received: from SR2-nishizuka.local (fujiko.nttv6.jp [IPv6:2402:c800:ff06:136::141]) by z.nttv6.jp (NTTv6MTA) with ESMTP id CCDBC3ACA5 for <dots@ietf.org>; Wed, 21 Oct 2015 15:07:59 +0900 (JST)
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com>
To: dots@ietf.org
From: kaname nishizuka <kaname@nttv6.jp>
X-Forwarded-Message-Id: <20151019191325.27117.43078.idtracker@ietfa.amsl.com>
Message-ID: <56272BC2.3070305@nttv6.jp>
Date: Wed, 21 Oct 2015 15:08:02 +0900
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <20151019191325.27117.43078.idtracker@ietfa.amsl.com>
Content-Type: multipart/alternative; boundary="------------060505060000030507030700"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/LwqQIKHJE43fJtJWbtQOy52Ey8I>
Subject: [Dots] Fwd: I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2015 06:08:03 -0000

This is a multi-part message in MIME format.
--------------060505060000030507030700
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit

Dear dots WG,

I've submitted individually the following draft which describes 
inter-domain dots usecases.

This document is based on DDoS protection technologies researched and 
developed by our team and generalized to meet dots usecases.
Please feel free to add a comment on the ML. We are willing to discuss them.
There would be needs to align concept with the existing usecase WG 
draft, but we'd like to make an emphasis on the inter-domain usecases.

Also, I'm looking forward to seeing you in Yokohama.


thank you,
kaname nishizuka
NTT Communications

-------- Forwarded Message --------
Subject: 	I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
Date: 	Mon, 19 Oct 2015 12:13:25 -0700
From: 	internet-drafts@ietf.org
Reply-To: 	internet-drafts@ietf.org
To: 	i-d-announce@ietf.org



A New Internet-Draft is available from the on-line Internet-Drafts directories.


         Title           : Inter-Domain DOTS Use Cases
         Author          : Kaname Nishizuka
	Filename        : draft-nishizuka-dots-inter-domain-usecases-00.txt
	Pages           : 15
	Date            : 2015-10-19

Abstract:
    This document describes inter-domain use cases of the DDoS Open
    Threat Signaling(DOTS).


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-nishizuka-dots-inter-domain-usecases/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-nishizuka-dots-inter-domain-usecases-00


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt




--------------060505060000030507030700
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=windows-1252">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Dear dots WG,<br>
    <br>
    I've submitted individually the following draft which describes
    inter-domain dots usecases.<br>
    <br>
    This document is based on DDoS protection technologies researched
    and developed by our team and generalized to meet dots usecases.<br>
    Please feel free to add a comment on the ML. We are willing to
    discuss them.<br>
    There would be needs to align concept with the existing usecase WG
    draft, but we'd like to make an emphasis on the inter-domain
    usecases.<br>
    <br>
    Also, I'm looking forward to seeing you in Yokohama.<br>
    <br>
    <div class="moz-forward-container"><br>
      thank you,<br>
      kaname nishizuka<br>
      NTT Communications<br>
      <br>
      -------- Forwarded Message --------
      <table class="moz-email-headers-table" border="0" cellpadding="0"
        cellspacing="0">
        <tbody>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Subject:
            </th>
            <td>I-D Action:
              draft-nishizuka-dots-inter-domain-usecases-00.txt</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Date: </th>
            <td>Mon, 19 Oct 2015 12:13:25 -0700</td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">From: </th>
            <td><a class="moz-txt-link-abbreviated" href="mailto:internet-drafts@ietf.org">internet-drafts@ietf.org</a></td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">Reply-To:
            </th>
            <td><a class="moz-txt-link-abbreviated" href="mailto:internet-drafts@ietf.org">internet-drafts@ietf.org</a></td>
          </tr>
          <tr>
            <th align="RIGHT" nowrap="nowrap" valign="BASELINE">To: </th>
            <td><a class="moz-txt-link-abbreviated" href="mailto:i-d-announce@ietf.org">i-d-announce@ietf.org</a></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <pre>A New Internet-Draft is available from the on-line Internet-Drafts directories.


        Title           : Inter-Domain DOTS Use Cases
        Author          : Kaname Nishizuka
	Filename        : draft-nishizuka-dots-inter-domain-usecases-00.txt
	Pages           : 15
	Date            : 2015-10-19

Abstract:
   This document describes inter-domain use cases of the DDoS Open
   Threat Signaling(DOTS).


The IETF datatracker status page for this draft is:
<a class="moz-txt-link-freetext" href="https://datatracker.ietf.org/doc/draft-nishizuka-dots-inter-domain-usecases/">https://datatracker.ietf.org/doc/draft-nishizuka-dots-inter-domain-usecases/</a>

There's also a htmlized version available at:
<a class="moz-txt-link-freetext" href="https://tools.ietf.org/html/draft-nishizuka-dots-inter-domain-usecases-00">https://tools.ietf.org/html/draft-nishizuka-dots-inter-domain-usecases-00</a>


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
<a class="moz-txt-link-freetext" href="ftp://ftp.ietf.org/internet-drafts/">ftp://ftp.ietf.org/internet-drafts/</a>

_______________________________________________
I-D-Announce mailing list
<a class="moz-txt-link-abbreviated" href="mailto:I-D-Announce@ietf.org">I-D-Announce@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/i-d-announce">https://www.ietf.org/mailman/listinfo/i-d-announce</a>
Internet-Draft directories: <a class="moz-txt-link-freetext" href="http://www.ietf.org/shadow.html">http://www.ietf.org/shadow.html</a>
or <a class="moz-txt-link-freetext" href="ftp://ftp.ietf.org/ietf/1shadow-sites.txt">ftp://ftp.ietf.org/ietf/1shadow-sites.txt</a>
</pre>
      <br>
    </div>
    <br>
  </body>
</html>

--------------060505060000030507030700--


From nobody Thu Oct 22 09:02:47 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1D631A1A98 for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 09:02:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vt4oug4oO3_r for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 09:02:43 -0700 (PDT)
Received: from mail-pa0-x22c.google.com (mail-pa0-x22c.google.com [IPv6:2607:f8b0:400e:c03::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68B061A0171 for <dots@ietf.org>; Thu, 22 Oct 2015 09:02:43 -0700 (PDT)
Received: by pacfv9 with SMTP id fv9so94437923pac.3 for <dots@ietf.org>; Thu, 22 Oct 2015 09:02:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=z5i82TrNJNrYlR1z6PTbZ/e1OTzpsN59uMO1mDOGWLY=; b=DIV9KXTmCW5gThCwxGOmnUZyIXyOhXUxlLqbKBj/Sr8Zb46pyFPR+cI1S/jpiStd6z HaCY/9cxQK5GwBbasqu+e37185bj9uhbOZ5Bw187BHs5FT1U/wljXq8Zj5q/ykUJtZBK x1T36ivGyUXEzq2jB+hZAUtN+ef0K5wkqsxS0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=z5i82TrNJNrYlR1z6PTbZ/e1OTzpsN59uMO1mDOGWLY=; b=YiLu2WTZAF06rKNL4OkEKKq86XQmDTNQAC0f+1X257NvJSqnhCG/LjapdmDH7JMyDY aW6f4XYj35cw0y7vzUH/BJSsY3Tx1lWONKNllQWulc1M+Jdhy1Nhw6k5AjBfVYiVv6uG LQbvR2+BHiSNAmEJ92FmzJPelP9w4QAu1Cl+aSRyEMIwraMRbBc7fLzlMuuz1qSva8MM xQLrRQAGy0idV5gFkqx8fK7JyW8atBqHfSCQ3kTLdtw4PQP4ED4v85VXZ032pbkiOwtW fO+qs3kp6dORNgV7YS0eyKub4Gej5lX62BNPAq3IvN7IdQBXWi8SNO/Gz5twa/y+uHBU 4jCg==
X-Gm-Message-State: ALoCoQnW9tDc98NcdXtNxOQy0Hm8gH+EzE3TY+TEWbp/DTZu2upaRqFReqe9tFiWxIWXZ1BNtZKO
X-Received: by 10.66.162.227 with SMTP id yd3mr18531646pab.53.1445529762829; Thu, 22 Oct 2015 09:02:42 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id dn4sm14558916pbd.0.2015.10.22.09.02.40 for <dots@ietf.org> (version=TLSv1 cipher=RC4-SHA bits=128/128); Thu, 22 Oct 2015 09:02:41 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots <dots@ietf.org>
Date: Thu, 22 Oct 2015 23:02:38 +0700
Message-ID: <A3D430E1-C0D8-4742-B6F5-310C4BCAB31F@arbor.net>
In-Reply-To: <5627F738.3060306@labs.htt-consult.com>
References: <20151019162244.18886.799.idtracker@ietfa.amsl.com> <2DD56D786E600F45AC6BDE7DA4E8A8C11217B7F1@eusaamb107.ericsson.se> <5627F738.3060306@labs.htt-consult.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/sdYo433g0DjLAUfnvULkSI62xzI>
Subject: Re: [Dots] New Version Notification for draft-ietf-dots-use-cases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Oct 2015 16:02:45 -0000

On 22 Oct 2015, at 3:36, Robert Moskowitz wrote:

> At some point I am going to have to offer alternative wording for some 
> of the run-on sentences like:

No one disagrees that there's considerable room for improvement.  The 
objective was to get something written down which encapsulated the core 
concepts while at the same time providing enough context for 
non-specialists to grasp the warp and woof of the thing; and to do so 
prior to the submission cutoff.

There's considerable repetitive verbiage in -00 because email 
discussions of the baseline concepts behind DOTS were taking up a great 
deal of time.  A brute-force approach to getting those concepts across 
in order to make the deadline was deemed to be the least time-consuming 
approach.  It seems to have been at least somewhat effective.

-01 will be a substantial stylistic re-write.

> That would at best be a 'C-' from my 7th grade english teacher!

Yes, well, better a 'C-' than an 'F' for not turning in the assignment 
on time.

The stylistic shortcomings of the -00 draft are not in dispute, and they 
will be rectified in -01.  In the cited example, the substitution of a 
period for a semicolon would resolve the issue, although I agree that it 
should (and will) be further improved.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Thu Oct 22 09:42:59 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2C471AD305 for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 09:42:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SAP7joqAEn8A for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 09:42:57 -0700 (PDT)
Received: from mail-pa0-x22d.google.com (mail-pa0-x22d.google.com [IPv6:2607:f8b0:400e:c03::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A59121AD0CB for <dots@ietf.org>; Thu, 22 Oct 2015 09:42:57 -0700 (PDT)
Received: by padhk11 with SMTP id hk11so91220612pad.1 for <dots@ietf.org>; Thu, 22 Oct 2015 09:42:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=UFx3yegjCKfR3Xwn0iw6yCpxXG1sinR4oTxUDWFUe6g=; b=Mw+jb47lLxo27a9guqQV/XCYXN7+Od/tICijVMsopCUjqBSpCzVc3eH9uK0y1pH94w zzL7Y5L/haeJ/5iGtLcIJTB+fH2HXfbEfTAWgb2ylj98mE4LTnwBFdCVXVEdnTd03gCQ AsItSOO8IZ7f+a7Ik2y1wn6/BNPmtFnL7pL88=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=UFx3yegjCKfR3Xwn0iw6yCpxXG1sinR4oTxUDWFUe6g=; b=i4jsr57uX7vocd/MOZeWhATIyxvbikX7dfnXzuV60AOGDIwTu2fi5DzDUUlrqmyBry uvJh2erM8LNS3caxW73TSpIlnLh/FLZNeM8cNae1NN8csat7bLAdRs+mpb/VH9iMtoib yS0puQpqjzJ0TpOKhFDiG0tOB/GEa8Dk14NBuKaxMA5WL4mUbRgzS4S37Vyc9zfjFfK0 Ujw+2HpuLuKWj7s9WahO29cmLTXu0icvg5+919hGKSLtTtdtgJOQiTUAlvaDl8lHtWWs E+ilGyse7kRmCp+UGEJO7Xe8+lq22sL9tcPM38TpGN+6xikR0JS0uZMlFDEDKuFYHizC ecgw==
X-Gm-Message-State: ALoCoQnwe7xjWWzistbaoPP0onUHTUSBMmqNFHuJXEgaywU4zdab8QrogqGBihfvrluKLmNP8K3i
X-Received: by 10.68.254.137 with SMTP id ai9mr18130556pbd.68.1445532177085; Thu, 22 Oct 2015 09:42:57 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id xm9sm14684003pbc.32.2015.10.22.09.42.55 for <dots@ietf.org> (version=TLSv1 cipher=RC4-SHA bits=128/128); Thu, 22 Oct 2015 09:42:56 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots@ietf.org
Date: Thu, 22 Oct 2015 23:42:53 +0700
Message-ID: <D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net>
In-Reply-To: <56272BC2.3070305@nttv6.jp>
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com> <56272BC2.3070305@nttv6.jp>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/NZC5rIAoyT3fCQLXCz7qy1L4plo>
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Oct 2015 16:42:58 -0000

On 21 Oct 2015, at 13:08, kaname nishizuka wrote:

> I've submitted individually the following draft which describes 
> inter-domain dots usecases.

This draft, along with previously-submitted drafts from several 
contributors, contains useful verbiage which should be incorporated into 
a document positing example deployment architectures and operational 
models, IMHO.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Thu Oct 22 19:41:28 2015
Return-Path: <xiaohong.deng@unsw.edu.au>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 800B81B3112 for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 19:41:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.507
X-Spam-Level: 
X-Spam-Status: No, score=-3.507 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_AU=0.377, HOST_EQ_AU=0.327, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CyB9OLtRNd0h for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 19:41:26 -0700 (PDT)
Received: from INFPACM004.services.comms.unsw.edu.au (smtp.unsw.edu.au [149.171.193.32]) by ietfa.amsl.com (Postfix) with ESMTP id 3ED4F1B310E for <dots@ietf.org>; Thu, 22 Oct 2015 19:41:25 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A2CvAgCdnSlW/zgaFKxehAp1viANgVmGHQKBRzgUAQEBAQEBAYEKhDIBAQUdHTQQCwIBBQMNAQMEAQELFBAyHQgCBAEaDIgcwTKERYZ3hH6EXDiDGoEUBZYrjnaHV48Hg3AfAkKEAz6FcYEGAQEB
X-IPAS-Result: A2CvAgCdnSlW/zgaFKxehAp1viANgVmGHQKBRzgUAQEBAQEBAYEKhDIBAQUdHTQQCwIBBQMNAQMEAQELFBAyHQgCBAEaDIgcwTKERYZ3hH6EXDiDGoEUBZYrjnaHV48Hg3AfAkKEAz6FcYEGAQEB
X-IronPort-AV: E=Sophos;i="5.20,185,1444654800"; d="scan'208";a="227730067"
Received: from unknown (HELO INFPWXH003.ad.unsw.edu.au) ([172.20.26.56]) by INFPACM004.services.comms.unsw.edu.au with ESMTP; 23 Oct 2015 13:30:44 +1100
Received: from INFPWXM010.ad.unsw.edu.au ([169.254.4.74]) by INFPWXH003.ad.unsw.edu.au ([172.20.26.56]) with mapi id 14.03.0248.002; Fri, 23 Oct 2015 13:30:45 +1100
From: Xiaohong Deng <xiaohong.deng@unsw.edu.au>
To: Roland Dobbins <rdobbins@arbor.net>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
Thread-Index: AQHRDOi4r/c7MlnhPkSiwBEAQFJWG554Vri1
Date: Fri, 23 Oct 2015 02:30:44 +0000
Message-ID: <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com> <56272BC2.3070305@nttv6.jp>,<D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net>
In-Reply-To: <D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net>
Accept-Language: en-GB, en-AU, en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [149.171.135.10]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/8p_N9B7B6DggnwtJRw2rTamiKuk>
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 02:41:27 -0000

Do you at very least care elaborating rationales behind your conclusive opi=
nion?=0A=
There have been times when IETF roughly follows: a new I-D - > presentation=
 -> feedbacks on site -> extensive discussion on Mailing-list -> Chairs cal=
l for opinions -> Chairs announce conclusive consensus if any-> loop back t=
o next round of presentation..IMHO.=0A=
Now it works a new fashion? Probably and hopefully not. I personally find t=
his kind of comments very confusing to the community.=0A=
________________________________________=0A=
From: Dots [dots-bounces@ietf.org] on behalf of Roland Dobbins [rdobbins@ar=
bor.net]=0A=
Sent: 23 October 2015 03:42=0A=
To: dots@ietf.org=0A=
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-=
00.txt=0A=
=0A=
On 21 Oct 2015, at 13:08, kaname nishizuka wrote:=0A=
=0A=
> I've submitted individually the following draft which describes=0A=
> inter-domain dots usecases.=0A=
=0A=
This draft, along with previously-submitted drafts from several=0A=
contributors, contains useful verbiage which should be incorporated into=0A=
a document positing example deployment architectures and operational=0A=
models, IMHO.=0A=
=0A=
=0A=
=0A=
-----------------------------------=0A=
Roland Dobbins <rdobbins@arbor.net>=0A=
=0A=
_______________________________________________=0A=
Dots mailing list=0A=
Dots@ietf.org=0A=
https://www.ietf.org/mailman/listinfo/dots=0A=


From nobody Thu Oct 22 21:58:45 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B79071B31BE for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 21:58:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 28eMmX6lNLJI for <dots@ietfa.amsl.com>; Thu, 22 Oct 2015 21:58:43 -0700 (PDT)
Received: from mail-pa0-x229.google.com (mail-pa0-x229.google.com [IPv6:2607:f8b0:400e:c03::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2A6B1B31BD for <dots@ietf.org>; Thu, 22 Oct 2015 21:58:43 -0700 (PDT)
Received: by padhk11 with SMTP id hk11so107275099pad.1 for <dots@ietf.org>; Thu, 22 Oct 2015 21:58:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=praWP7tpDp74uG4fRtxK/xpha7LT3Qf/7snp9ZHxVxc=; b=ShEb5TbLeK5nvbrvAiLY6nnrWoDUVQPWRYH8dF1bRdgLWp9E6/BmHcIwBj7andQbEV 4U8Au6P8NzP5A4POkpfsVcoyS2NfsB+KwbEcTx8wwhQVOyAyCTLoOruLBs0u9HQogEVH ccXwiu+I/CZZHKpxp+xbOligEYuummU5L9GGA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=praWP7tpDp74uG4fRtxK/xpha7LT3Qf/7snp9ZHxVxc=; b=AQf255KIyiQhgx1uCaGvNroEh/oyVKnrytbnVWXpl9I6ACb57ppjMloxjo/jHVVhbE lVQ47nNg2092rVEGV+e40bAY8O103yVkrzt5d8q4+siJnfRQRsgcnb6+qgk1hM4B2Mp7 4Gyz3IKMCvIBzSUt2TfE6rPBQ/8MzYMVXjmnbNhD2PsQbsWVvNbWu3tWPAS3kt+9//uO HaT/qEDx6RBVx6ODD0ae2ywZeW8xid/ZftN2rRAth6f8VXzE7hHmdDvi+HfO8IdX5rCe SAKW02wDUlC3Py1o0MaLSkRfirdVXG2cN1QdqxBu2lFvxxlChVk6TvnRu5ONJwI6sPej XyiA==
X-Gm-Message-State: ALoCoQnJsK64CXJMsqnj/2+H4eyHjP0Rq29fNIaPetmMQmsiEPhnyJmSahyQuuDkfAqY5AslKU1Z
X-Received: by 10.68.135.1 with SMTP id po1mr2805544pbb.23.1445576323310; Thu, 22 Oct 2015 21:58:43 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id ou3sm16575169pbb.44.2015.10.22.21.58.41 for <dots@ietf.org> (version=TLSv1 cipher=RC4-SHA bits=128/128); Thu, 22 Oct 2015 21:58:42 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: "dots@ietf.org" <dots@ietf.org>
Date: Fri, 23 Oct 2015 11:58:38 +0700
Message-ID: <9C02D897-22FE-4001-8495-5D4206CA8A02@arbor.net>
In-Reply-To: <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com> <56272BC2.3070305@nttv6.jp> <D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net> <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/WJIXuGWIwVzfxLT9hg4B5Q3Ga6o>
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 04:58:44 -0000

On 23 Oct 2015, at 9:30, Xiaohong Deng wrote:

> Do you at very least care elaborating rationales behind your 
> conclusive opinion?

No *conclusive* opinion was offered.

> Now it works a new fashion? Probably and hopefully not. I personally 
> find this kind of comments very confusing to the community.

IMHO = In My Humble Opinion = 'this is what I as an individual think'.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Fri Oct 23 02:02:06 2015
Return-Path: <xiaohong.deng@unsw.edu.au>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3B0D01B3361 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 02:02:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.507
X-Spam-Level: 
X-Spam-Status: No, score=-3.507 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_AU=0.377, HOST_EQ_AU=0.327, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rzbf8d82KFMB for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 02:01:58 -0700 (PDT)
Received: from INFPACM004.services.comms.unsw.edu.au (smtp.unsw.edu.au [149.171.193.32]) by ietfa.amsl.com (Postfix) with ESMTP id ED6E11B3362 for <dots@ietf.org>; Fri, 23 Oct 2015 02:01:57 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A2D7AQAf9ylW/zgaFKxegzZUbwa+IAENgVkXCoV8AoFFOBQBAQEBAQEBgQqEMgEBAQMBAQEBNzQQCwIBBQMNAQMEAQELFBAnCx0IAgQBEggMiBQIDcEbhBgBAQEBAQEEAQEBAQEBAQEXBIZ3hH6EXDiDGoEUAQSHQI5rjnaHV48Hg3AfAQFCghEdgVU+NIU9gQYBAQE
X-IPAS-Result: A2D7AQAf9ylW/zgaFKxegzZUbwa+IAENgVkXCoV8AoFFOBQBAQEBAQEBgQqEMgEBAQMBAQEBNzQQCwIBBQMNAQMEAQELFBAnCx0IAgQBEggMiBQIDcEbhBgBAQEBAQEEAQEBAQEBAQEXBIZ3hH6EXDiDGoEUAQSHQI5rjnaHV48Hg3AfAQFCghEdgVU+NIU9gQYBAQE
X-IronPort-AV: E=Sophos;i="5.20,186,1444654800"; d="scan'208";a="227847011"
Received: from unknown (HELO INFPWXH003.ad.unsw.edu.au) ([172.20.26.56]) by INFPACM004.services.comms.unsw.edu.au with ESMTP; 23 Oct 2015 20:01:56 +1100
Received: from INFPWXM010.ad.unsw.edu.au ([169.254.4.74]) by INFPWXH003.ad.unsw.edu.au ([172.20.26.56]) with mapi id 14.03.0248.002; Fri, 23 Oct 2015 20:01:56 +1100
From: Xiaohong Deng <xiaohong.deng@unsw.edu.au>
To: Roland Dobbins <rdobbins@arbor.net>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
Thread-Index: AQHRDOi4r/c7MlnhPkSiwBEAQFJWG554Vri1//92BACAAPveNQ==
Date: Fri, 23 Oct 2015 09:01:55 +0000
Message-ID: <36ADAEDEF1F28546BC414651D641DDAB0EDD8A8B@INFPWXM010.ad.unsw.edu.au>
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com> <56272BC2.3070305@nttv6.jp> <D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net> <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>, <9C02D897-22FE-4001-8495-5D4206CA8A02@arbor.net>
In-Reply-To: <9C02D897-22FE-4001-8495-5D4206CA8A02@arbor.net>
Accept-Language: en-GB, en-AU, en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [149.171.135.10]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/BwAgVw8rEbi3sYZKvgS5rJhTVOQ>
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 09:02:01 -0000

Thanks for the clarification then; it did sound such before..=0A=
________________________________________=0A=
From: Dots [dots-bounces@ietf.org] on behalf of Roland Dobbins [rdobbins@ar=
bor.net]=0A=
Sent: 23 October 2015 15:58=0A=
To: dots@ietf.org=0A=
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-=
00.txt=0A=
=0A=
On 23 Oct 2015, at 9:30, Xiaohong Deng wrote:=0A=
=0A=
> Do you at very least care elaborating rationales behind your=0A=
> conclusive opinion?=0A=
=0A=
No *conclusive* opinion was offered.=0A=
=0A=
> Now it works a new fashion? Probably and hopefully not. I personally=0A=
> find this kind of comments very confusing to the community.=0A=
=0A=
IMHO =3D In My Humble Opinion =3D 'this is what I as an individual think'.=
=0A=
=0A=
-----------------------------------=0A=
Roland Dobbins <rdobbins@arbor.net>=0A=
=0A=
_______________________________________________=0A=
Dots mailing list=0A=
Dots@ietf.org=0A=
https://www.ietf.org/mailman/listinfo/dots=0A=


From nobody Fri Oct 23 12:15:44 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E2A6B1A8893 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:15:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level: 
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hgiHYm5_F5Zk for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:15:41 -0700 (PDT)
Received: from plainfield.sei.cmu.edu (plainfield.sei.cmu.edu [192.58.107.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32A581A8837 for <dots@ietf.org>; Fri, 23 Oct 2015 12:15:40 -0700 (PDT)
Received: from pawpaw.sei.cmu.edu (pawpaw.sei.cmu.edu [10.64.21.22]) by plainfield.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9NJFdV2021777; Fri, 23 Oct 2015 15:15:39 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1445627739; bh=c/MhJXHolFHqVpfqSaVDhQCAKN7kxCZTmkc78Y8XbYU=; h=From:To:Subject:Date:Message-ID:References:In-Reply-To: Content-Type:Content-Transfer-Encoding:MIME-Version:Sender: Reply-To:Cc; b=iJJ/hirW7hyX+IKWSHuY2dMTJ1ukx7Ma/af8haP/h5oQSjyrmQQk7lEPgMg34dRo+ RhW9jcmnkhHBd+io3FTjtfymx88kkdT+3tWKw5N3oRYJotQRNCW3IeST6/ix94OCe6 oseI7HwgplWuAUEqsNYKQaZ0MUAWVMnd/F57qVJQ=
Received: from CASSINA.ad.sei.cmu.edu (cassina.ad.sei.cmu.edu [10.64.28.249]) by pawpaw.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9NJFiDa002174; Fri, 23 Oct 2015 15:15:44 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASSINA.ad.sei.cmu.edu ([10.64.28.249]) with mapi id 14.03.0248.002; Fri, 23 Oct 2015 15:15:34 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: Roland Dobbins <rdobbins@arbor.net>, dots <dots@ietf.org>
Thread-Topic: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRChKBgy392uVC4EubFSU1bnOiOZ5yErmAgABV4QCAAAQ9AIACgcyAgAR3nSA=
Date: Fri, 23 Oct 2015 19:15:33 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD9534B3B@marathon>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net>
In-Reply-To: <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/yyg7SmPlWR0yhICRwTF6Su2zbbs>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 19:15:43 -0000

Hello WG!

> -----Original Message-----
> From: Dots [mailto:dots-bounces@ietf.org] On Behalf Of Roland Dobbins
> Sent: Tuesday, October 20, 2015 1:51 PM
> To: dots <dots@ietf.org>
> Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-
> extension-00.txt
>=20
> On 19 Oct 2015, at 10:33, Xialiang (Frank) wrote:

[snip]

> > [Frank]: From my perspective, this draft is related to the potential
> > use of IPFIX for the attack telemetry.
>=20
> Which is not within the scope of this WG.

The WG chairs in consultation with the AD have reviewed this question of sc=
ope given our charter [1].  We're all in agreement that exploring protocol =
solutions in attack telemetry and IPFIX is in scope for the WG. While the W=
G hasn't reached consensus on the exact requirements or use cases, early pr=
otocol discussion in draft-fu-dots-ipfix-extension-00  (or draft-reddy-dots=
-transport-01) will help inform the direction of the group and get us close=
r to WG data model and protocol specifications.=20

We hope this clarifies this scope question and we can continue to focus on =
progressing our work as a WG. If there are any questions or concerns, pleas=
e let us know and we will be happy to help.=20

Roman & Tobias
(DOTS co-chairs)

[1] http://datatracker.ietf.org/wg/dots/charter/


From nobody Fri Oct 23 12:21:49 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3A0911A8997 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:21:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level: 
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZtK5PmvsSRCa for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:21:46 -0700 (PDT)
Received: from shetland.sei.cmu.edu (shetland.sei.cmu.edu [192.58.107.44]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B6E891A8996 for <dots@ietf.org>; Fri, 23 Oct 2015 12:21:46 -0700 (PDT)
Received: from pawpaw.sei.cmu.edu (pawpaw.sei.cmu.edu [10.64.21.22]) by shetland.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9NJLjIr003076 for <dots@ietf.org>; Fri, 23 Oct 2015 15:21:45 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1445628105; bh=7Ir5HeQjcgzmWyFK5/5wQjdJHQxkqXhAvBjVNa6L+a0=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=Cj2miHT1/ZCLW5NxMsupZ08iZjPk93je7brBC8zLaFAAvoDA5OXSmuQXmOp4n8/zF fSnM9covVNGq9xe4t85w4xbRMZbJ2C2wJI2MUFp2pmtffryC88qJJqZ/JbC/CjxneV +S3s8flHCu4yiY8Ea2s4NDOVqGNjCaFkAbBbr794=
Received: from CASCADE.ad.sei.cmu.edu (cascade.ad.sei.cmu.edu [10.64.28.248]) by pawpaw.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9NJLrYc002871 for <dots@ietf.org>; Fri, 23 Oct 2015 15:21:53 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASCADE.ad.sei.cmu.edu ([10.64.28.248]) with mapi id 14.03.0248.002; Fri, 23 Oct 2015 15:21:43 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: dots <dots@ietf.org>
Thread-Topic: IETF 94 Agenda
Thread-Index: AdENx4CiQlB26qpJTGKWoCgBoj3vpw==
Date: Fri, 23 Oct 2015 19:21:42 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD9534BCE@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/g9ifTiXTwDYDkm1tREN6u3GTEyc>
Subject: [Dots] IETF 94 Agenda
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 19:21:48 -0000

Hello WG,

An updated agenda for the DOTS meetings at IETF 94 is available at [1].=20

=3D=3D[ snip]=3D=3D
DDoS Open Threat Signaling (DOTS) WG Agenda

TUESDAY, November 3, 2015
1300-1500  Afternoon Session I
Room 501  SEC  dots  DDoS Open Threat Signaling WG

Co-Chairs: Roman Danyliw and Tobias Gondrom

1. Note well, logistics and introduction (chairs, 5 min)

2. Use Case Discussion (50 min)=20
   - draft-ietf-dots-use-cases-00 (Roland Dobbins, 30 min)
   - draft-nishizuka-dots-inter-domain-usecases-00 (Kaname Nishizuka, 10 mi=
n)
   - Additional use cases discussion (10 min)

3. Requirements Discussion (30 min)
   - draft-ietf-dots-requirements-00 (Andrew Mortensen, 20 min)
   - Additional requirements discussion (10 min)

4. Additional Drafts (40 min)
  - draft-reddy-dots-transport-01 (Prashanth Patil, 10 min)
  - Discussion (5 min)
  - draft-fu-dots-ipfix-extension-00 (Frank Xia Liang, 10 min)
  - Discussion (5 min)=20

5. Closing (5 min)
  - Closing discuss
  - Way ahead summary
  - Interim Meeting in January/February
=3D=3D[ snip]=3D=3D

If there are additional topics to add, please let your interest be known to=
 the chairs as soon as possible.

Regards,
Roman and Tobias

[1] https://www.ietf.org/proceedings/94/agenda/agenda-94-dots


From nobody Fri Oct 23 12:25:55 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E34F81A89A7 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:25:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level: 
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8kL28pMOqKP7 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 12:25:53 -0700 (PDT)
Received: from plainfield.sei.cmu.edu (plainfield.sei.cmu.edu [192.58.107.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 80F731A8877 for <dots@ietf.org>; Fri, 23 Oct 2015 12:25:53 -0700 (PDT)
Received: from pawpaw.sei.cmu.edu (pawpaw.sei.cmu.edu [10.64.21.22]) by plainfield.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9NJPpMq021957; Fri, 23 Oct 2015 15:25:51 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1445628351; bh=6VGte4Fpg+5HUj7Xb8USQka0gq8VqOKjpXknjR3D0M0=; h=From:To:Subject:Date:Message-ID:References:In-Reply-To: Content-Type:Content-Transfer-Encoding:MIME-Version:Sender: Reply-To:Cc; b=CdVIkcql7R3auG7tXMsXiOW2WxWvQKhfzDHdyazoFGJ9di5Ucnypp8A/njYR5uRMX 182dntTZ+xftflhx83vMhtoLfyYwPbHHSJK3HSvNzVZcYVXXt8bW4m43DnHj85WoU2 /ESDkQEPmrj/S/p6RvhzrBJmdcjLL21o5FVKpdrI=
Received: from CASSINA.ad.sei.cmu.edu (cassina.ad.sei.cmu.edu [10.64.28.249]) by pawpaw.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9NJPxhS003272; Fri, 23 Oct 2015 15:26:00 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASSINA.ad.sei.cmu.edu ([10.64.28.249]) with mapi id 14.03.0248.002; Fri, 23 Oct 2015 15:25:49 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: Xiaohong Deng <xiaohong.deng@unsw.edu.au>, Roland Dobbins <rdobbins@arbor.net>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
Thread-Index: AQHRDOi9MtvwT4AUHE6pFZKD4BUgU554nt8AgADXtJA=
Date: Fri, 23 Oct 2015 19:25:49 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD9534BEA@marathon>
References: <20151019191325.27117.43078.idtracker@ietfa.amsl.com> <56272BC2.3070305@nttv6.jp>,<D83B3E06-757A-45B5-B7AE-B0442802C3E7@arbor.net> <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>
In-Reply-To: <36ADAEDEF1F28546BC414651D641DDAB0EDD8A74@INFPWXM010.ad.unsw.edu.au>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/rNxFdcEcHTUnw7PDZuKk94bR_cM>
Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecases-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 19:25:55 -0000

Hello WG!

Per the IETF 94 agenda [1], draft-nishizuka-dots-inter-domain-usecases-00 w=
ill be presented to the WG during the use case discussions.

Roman

[1] https://www.ietf.org/proceedings/94/agenda/agenda-94-dots

> -----Original Message-----
> From: Dots [mailto:dots-bounces@ietf.org] On Behalf Of Xiaohong Deng
> Sent: Thursday, October 22, 2015 10:31 PM
> To: Roland Dobbins <rdobbins@arbor.net>; dots@ietf.org
> Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecase=
s-
> 00.txt
>=20
> Do you at very least care elaborating rationales behind your conclusive
> opinion?
> There have been times when IETF roughly follows: a new I-D - > presentati=
on
> -> feedbacks on site -> extensive discussion on Mailing-list -> Chairs ca=
ll for
> opinions -> Chairs announce conclusive consensus if any-> loop back to ne=
xt
> round of presentation..IMHO.
> Now it works a new fashion? Probably and hopefully not. I personally find
> this kind of comments very confusing to the community.
>
> _______________________________________
> From: Dots [dots-bounces@ietf.org] on behalf of Roland Dobbins
> [rdobbins@arbor.net]
> Sent: 23 October 2015 03:42
> To: dots@ietf.org
> Subject: Re: [Dots] I-D Action: draft-nishizuka-dots-inter-domain-usecase=
s-
> 00.txt
>=20
> On 21 Oct 2015, at 13:08, kaname nishizuka wrote:
>=20
> > I've submitted individually the following draft which describes
> > inter-domain dots usecases.
>=20
> This draft, along with previously-submitted drafts from several contribut=
ors,
> contains useful verbiage which should be incorporated into a document
> positing example deployment architectures and operational models, IMHO.
>=20
>=20
>=20
> -----------------------------------
> Roland Dobbins <rdobbins@arbor.net>


From nobody Fri Oct 23 21:39:59 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42EEC1A9097 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 21:39:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ksr7AwTqMXsf for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 21:39:56 -0700 (PDT)
Received: from mail-pa0-x229.google.com (mail-pa0-x229.google.com [IPv6:2607:f8b0:400e:c03::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C70891A8F44 for <dots@ietf.org>; Fri, 23 Oct 2015 21:39:56 -0700 (PDT)
Received: by padhk11 with SMTP id hk11so135336006pad.1 for <dots@ietf.org>; Fri, 23 Oct 2015 21:39:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-type; bh=iI85ILBJsMvhnVhY7F0y5gyplRvsytB/NPqcJrZwWjU=; b=gG1iIw+GfZ2nUXa88VKd3hYIJ9PcM5hF2lszoLZPzhpLpbd+ARjrfndNu+5zaJGEcs heGiMkPMXxZKsGeTI/3YaJY/+S3+D+6eYve0NqbOMeNHo45Zb6a2cAGqetPDE4W8XbAH hl1zzc9fjnLZ4W+/sn/CVmkue/ACuymNVHYSA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=iI85ILBJsMvhnVhY7F0y5gyplRvsytB/NPqcJrZwWjU=; b=NVIJxkwSe0lreldi9k7KuYAcGmeZxBeOoGqr8EeLu8bdMApm8hXyq15cxsszJqn6v2 tCOTBzWd25tySJY00G6fXfDLcBUFxvTdZC2I/nsWoy9PtadbPChVrunn0tqGXJrQ0HWn Rcnte5kHSmiecGWcB08Fttbs0u6gnmEbudsXfzPDm53SYae4Mj2M1qPm2/4C9jYcmgOw Wio9bd0Pozh57iKiJ/UU89UIA6towZC/hnjX69yF4jfC5B3oGdtB4jJgn4DAdP7TPgVD uU7/6iM+uoJcqncBmRtyL4iVIIA/TM11psvoFyALyuKLX/YbLs5MCc1LINMFa5B/iGZI MTIA==
X-Gm-Message-State: ALoCoQnC/qGY9Pi1XhpYqGjtenT5lnKvhlwCQ1l/YUkvWSUxa77I3566AQokL8QBCZk/AKCPFXkv
X-Received: by 10.68.138.129 with SMTP id qq1mr9189403pbb.35.1445661596305; Fri, 23 Oct 2015 21:39:56 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id er1sm11342920pbb.6.2015.10.23.21.39.53 (version=TLSv1 cipher=RC4-SHA bits=128/128); Fri, 23 Oct 2015 21:39:55 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: "Tobias Gondrom" <tobias.gondrom@gondrom.org>
Date: Sat, 24 Oct 2015 11:39:51 +0700
Message-ID: <1EE67EAE-4EBB-4BC3-96D9-281EE2A40E83@arbor.net>
In-Reply-To: <561179CA.3020107@gondrom.org>
References: <561179CA.3020107@gondrom.org>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/BXYmWid52ODptyO7jYHFRNSKf98>
Cc: rdd@cert.org, dots@ietf.org
Subject: Re: [Dots] Reminder on the charter of DOTS and that multiple scenarios are in scope
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Oct 2015 04:39:58 -0000

[I apparently missed this message on 5Oct2015; apologies for the late 
reply!]

On 5 Oct 2015, at 2:11, Tobias Gondrom wrote:

> "The aim of DDoS Open Threat Signaling (DOTS) is to develop a 
> standards based approach for the realtime signaling of DDoS related 
> telemetry and threat handling requests and data between elements 
> concerned with DDoS attack detection, classification, traceback, and 
> mitigation.")

As a WG participant who contributed to that specific wording in the 
charter, please allow me to clarify its intended meaning.

The 'telemetry' part was not meant to imply that the DOTS WG should take 
on the huge task of further redefining existing telemetry standards such 
as IPFIX as a goal in and of itself.  This is a much bigger job with 
implications far beyond the realm of threat signaling.

The intent was to ensure that we could potentially utilize existing 
telemetry mechanisms for the purpose of signaling and communicating 
threat handling requests, and to potentially explore the extension of 
those standards, if necessary, in order to enhance their suitability for 
the threat signaling and the communication of threat handling requests, 
nothing more.  The emphasis was meant to be on the 'signaling' and 
'threat handling' parts, not the 'telemetry' parts.

Very specifically, 'signaling of DDoS related telemetry' does not imply 
'redefinition of DDoS related telemetry'.

> We should be careful to avoid individual attempts of 
> re-interpretations

The above is not in fact a re-interpretation; as the WG participant who 
contributed the specific verbiage in question, it is a statement of the 
literal meaning of the verbiage in question by the individual who 
contributed it to the DOTS WG charter.

See <http://www.ietf.org/mail-archive/web/dots/current/msg00131.html>.

> based on company perspectives about what would be out-of-scope of the 
> WG.

To clarify, expressed views regarding the expansion of the scope of the 
DOTS WG beyond threat signaling are wholly unrelated to company 
perspectives.

They are the expression of legitimate concerns by individual 
contributors to the DOTS WG that by expanding the focus of the DOTS WG 
beyond the realm of threat signaling, we are inadvertently embracing a 
much larger task than establishing a standards-based mechanism for 
threats-signaling and which has the potential to jeopardizes our ability 
to focus on the completion of the DOTS WG goal of establishing a 
standards-based mechanism within a relatively short timeframe.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Fri Oct 23 21:55:00 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 894EF1ACD74 for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 21:54:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6NfPW4vtytia for <dots@ietfa.amsl.com>; Fri, 23 Oct 2015 21:54:57 -0700 (PDT)
Received: from mail-pa0-x235.google.com (mail-pa0-x235.google.com [IPv6:2607:f8b0:400e:c03::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C91941ACD6C for <dots@ietf.org>; Fri, 23 Oct 2015 21:54:57 -0700 (PDT)
Received: by pasz6 with SMTP id z6so135318646pas.2 for <dots@ietf.org>; Fri, 23 Oct 2015 21:54:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-type; bh=Spw+TTAERVYfbeOzO/aQvBhcovRbryXudxZiTmpjOu0=; b=Z/FjwtqAASXkF8BafGRP5GyCQUV4RKvBJ9n+AGmOpeKMfRJ0/5slHcrsblkZxb6ys3 KtI+1k5/Fo65Qr7588CT/1Dgt/BP+1IyqRv2wa2kXzRNVRgJrELj1ISMtpW1ctfXLVQq o6z7CGqIMXyEtypeU75lj3fyHhsmkPLCpWnz4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=Spw+TTAERVYfbeOzO/aQvBhcovRbryXudxZiTmpjOu0=; b=apn/dZ9ucDBnhNSFWNvpw6jPArbrE8gxtsUx30jWZgbLUzirWAx1lbTFniA2abD3L2 YX9WR6bZPRrfq68KTV/xlK06OD9I/dyTtw5ghdCyes9PhSvGv3WhQggmFIVlBWcAvW/D fy6ifwlvyoCQne6ilaC69Pzol+fztfG7E9nD3FWhoRimfwXs5gI+S2cT1459kPaZAStt jcAhnIlGgzBRHUqzHB+ug3s7j8ROfTg62KnpCa8/iRID8U6s68vKfgWbAGtq7X9JBu59 Wgrv87Ek0CKt9PYUrPFf5pbVVI5ybWuiWbeZma3nmZ/RecBZGaQLVCbZ5XWP6k6XU420 DfNA==
X-Gm-Message-State: ALoCoQnv+zwb9Vww71Wu2RtxI0AsL6XX8KEwjBH+llOhHZc79KHkYCkCWQVZR7q4bYA3f6MXLcYv
X-Received: by 10.66.141.42 with SMTP id rl10mr28269040pab.18.1445662497326; Fri, 23 Oct 2015 21:54:57 -0700 (PDT)
Received: from [172.19.254.135] (202-176-81-112.static.asianet.co.th. [202.176.81.112]) by smtp.gmail.com with ESMTPSA id t9sm21829316pbs.17.2015.10.23.21.54.55 (version=TLSv1 cipher=RC4-SHA bits=128/128); Fri, 23 Oct 2015 21:54:56 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots <dots@ietf.org>
Date: Sat, 24 Oct 2015 11:54:52 +0700
Message-ID: <98F23B2C-7398-4449-99DF-66FA05D99FD2@arbor.net>
In-Reply-To: <359EC4B99E040048A7131E0F4E113AFCD9534B3B@marathon>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net> <359EC4B99E040048A7131E0F4E113AFCD9534B3B@marathon>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/caFdWsatuwdx20oehv4b44vhyj0>
Cc: "Roman D. Danyliw" <rdd@cert.org>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Oct 2015 04:54:59 -0000

On 24 Oct 2015, at 2:15, Roman D. Danyliw wrote:

> If there are any questions or concerns, please let us know and we will 
> be happy to help.

The intent of the language in the charter discussing existing telemetry 
standards was to ensure that the DOTS WG had the option of utilizing 
and/or exploring the extension of said standards within the realm of 
using them for threat signaling and request handling purposes; this was 
the spirit in which it was contributed:

<http://www.ietf.org/mail-archive/web/dots/current/msg00131.html>

The concern is that by getting into details of telemetry format 
definition which are unrelated to threat signaling, we are inadvertently 
embracing the much larger task of general telemetry format redefinition, 
which has implications far beyond the threat signaling arena and is a 
much larger, more involved, and more complex task than defining a threat 
signaling standard.

draft-fu-dots-ipfix-extension-00 is not related to threat signaling.  It 
is related to the underlying generation and export of network traffic 
statistics and characteristics.  From draft-fu-dots-ipfix-extension-00:

    This document presents the IPFIX IEs which are available for the
    network attacks detection, some of them are the new defined IPFIX
    IEs and their formats are specified. The wise utilization of these
    IEs will improve the network security and will support the offline
    analysis of data from different operators in the future with minimal
    resource consumption.

There is nothing in draft-fu-dots-ipfix-extension-00 which relates to 
threat signaling.  Nowhere in draft-fu-dots-ipfix-extension-00 is the 
topic of threat signaling mentioned, even in passing.

I apparently missed an email message from the chairs to the list on this 
topic on 5Oct2015; apologies for this oversight.  The concerns expressed 
above are not based upon any company perspective, as was implied in that 
message, but are the concerns of an individual contributor to the WG 
that we are at risk of inadvertently taking on tasks which are outside 
the realm of threat signaling, thereby making it more difficult to 
accomplish our primary goal of developing a standardized mechanism for 
DDoS threat signaling.

These concerns relate to the risk of inadvertent WG scope-creep, nothing 
more.

 From the DOTS charter:

-----

Any modification of or extension to existing protocols must be in close 
coordination with the working
groups responsible for the protocol being modified, and may be done in 
this working group after agreement with all the relevant WGs and 
responsible Area Directors.

-----

Has this coordination with regards to draft-fu-dots-ipfix-extension-00 
taken place, and has the agreement of the Operations and Management Area 
AD and the IPFIX chairs to this proposed modification to IPFIX been 
secured?

Many thanks!

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Sat Oct 24 01:35:01 2015
Return-Path: <nteague@verisign.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D0741B2CD4 for <dots@ietfa.amsl.com>; Sat, 24 Oct 2015 01:35:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gY-Sq9WhbSBD for <dots@ietfa.amsl.com>; Sat, 24 Oct 2015 01:34:58 -0700 (PDT)
Received: from mail-oi0-f98.google.com (mail-oi0-f98.google.com [209.85.218.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BB7B31B2CCE for <dots@ietf.org>; Sat, 24 Oct 2015 01:34:58 -0700 (PDT)
Received: by oifu187 with SMTP id u187so10707841oif.1 for <dots@ietf.org>; Sat, 24 Oct 2015 01:34:58 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:thread-topic:thread-index :date:message-id:references:in-reply-to:accept-language :content-language:content-type:content-transfer-encoding :mime-version; bh=E04xBLleGMbE7vUcdZEeEMt1wHLQAq6TvXNN0Spq1tc=; b=NnpRgkdpNVpbghISwUOsSi8d/ZC/0x64D0MpqjOwbE2Xd9h1w20JT7NnSBjSZ1bibx VQli1ARc2A3sccczG1afxi99dvur+pJCPrTquUEfJ+S//E7qR18HOVmjPDhCFTPjMwuq Gsu8x03KTZHcgSMcPO3DCY+NtYt9mLSF3YQl3oDuObCu4sEwvEWJkIs0IEobJyyMDFwf SURNjColAs+q0vlzXI6t8BPb5A2RwBYan7aEUJQqSNK/lwqQa2lmHzUusxyIioUj7KNu ekYGQbCI4yvmBi2kRPBBbNRLg/Os7QVSEblmeP+JGce2avb6abLD6xQ6W9E72W/eWr4q N0tA==
X-Gm-Message-State: ALoCoQmWFFW2yhTu1bRtSiElY6qyG5FOonOQxfehqZPb9Hft7yVsOIx+lOVeE/zEEgZZvFKb3hFEL9q2ualiKhGroW2xTtPLLw==
X-Received: by 10.140.97.7 with SMTP id l7mr30777211qge.32.1445675698060; Sat, 24 Oct 2015 01:34:58 -0700 (PDT)
Received: from brn1lxmailout01.verisign.com (brn1lxmailout01.verisign.com. [72.13.63.41]) by smtp-relay.gmail.com with ESMTPS id m69sm2741525qki.3.2015.10.24.01.34.57 (version=TLSv1 cipher=RC4-SHA bits=128/128); Sat, 24 Oct 2015 01:34:58 -0700 (PDT)
X-Relaying-Domain: verisign.com
Received: from brn1wnexcas01.vcorp.ad.vrsn.com (brn1wnexcas01 [10.173.152.205]) by brn1lxmailout01.verisign.com (8.13.8/8.13.8) with ESMTP id t9O8Yv4e032080 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Sat, 24 Oct 2015 04:34:57 -0400
Received: from BRN1WNEXMBX01.vcorp.ad.vrsn.com ([::1]) by brn1wnexcas01.vcorp.ad.vrsn.com ([::1]) with mapi id 14.03.0174.001; Sat, 24 Oct 2015 04:34:56 -0400
From: "Teague, Nik" <nteague@verisign.com>
To: Roland Dobbins <rdobbins@arbor.net>
Thread-Topic: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRC1/kNHmr6l8w4UaxDeXhE0BYxp55uq6AgACh3AD///pvVA==
Date: Sat, 24 Oct 2015 08:34:56 +0000
Message-ID: <5DA95CE7-ED2D-495A-933E-D2BD107075DA@Verisign.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net> <359EC4B99E040048A7131E0F4E113AFCD9534B3B@marathon>, <98F23B2C-7398-4449-99DF-66FA05D99FD2@arbor.net>
In-Reply-To: <98F23B2C-7398-4449-99DF-66FA05D99FD2@arbor.net>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/81Sq1WMo6lH0L4H6JQZ8ww5Dm5g>
Cc: "Roman D. Danyliw" <rdd@cert.org>, dots <dots@ietf.org>
Subject: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Oct 2015 08:35:00 -0000

On 24 Oct 2015, at 05:55, Roland Dobbins <rdobbins@arbor.net> wrote:

>> On 24 Oct 2015, at 2:15, Roman D. Danyliw wrote:
>>=20
>> If there are any questions or concerns, please let us know and we will b=
e happy to help.

My 2c

A lot of this discussion is somewhat distracting from the fact that use cas=
es will drive requirements and in turn drive the end result... if that's IP=
FIX or pigeons is not a direct concern atm.

Thanks,

-Nik=


From nobody Sun Oct 25 12:24:11 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E6881B3087 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 12:24:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -94.765
X-Spam-Level: 
X-Spam-Status: No, score=-94.765 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XB8sNKL-EOMg for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 12:24:08 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9D7E1B3088 for <dots@ietf.org>; Sun, 25 Oct 2015 12:24:07 -0700 (PDT)
Received: from [192.168.178.26] (x590f7e4f.dyn.telefonica.de [89.15.126.79]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 8BDA762DD5 for <dots@ietf.org>; Sun, 25 Oct 2015 20:24:05 +0100 (CET)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=D2/g4bdjoc+8c/ILmv5Siuk7HJc7wq0OCHYuw65mapG6g0Jms6QrTDwNPKQM0bKipSrep5tB6sTLI1q0hZE8Lw3d9R14m6HfnDHLKZpbg+ddviQXx0NHrnDIw9QcmulT67Q4eD/YsvzAyXvKl55n/3nr3Nex5Y+hH2ZLY2jXuOU=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:Content-Type;
Message-ID: <562D2C55.3020704@gondrom.org>
Date: Sun, 25 Oct 2015 20:24:05 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: dots@ietf.org
Content-Type: multipart/alternative; boundary="------------010907000801050006050509"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/YaHaxX77ygwpeZ_iuegELIPQTXU>
Subject: [Dots] DOTS work priorities: encourage to start protocol work in parallel to use cases and requirements
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Oct 2015 19:24:10 -0000

This is a multi-part message in MIME format.
--------------010907000801050006050509
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Dear DOTS WG,

it is great to see that so many first drafts have come in.
And we are very happy to see that the first versions of the use case, 
requirements and protocol drafts have been posted.

We like to encourage people to start thinking and working on protocol 
drafts in parallel to the existing use case and requirements.

We appreciate that protocol drafts are the answer to use cases and 
requirements. But equally they can help to inform the use case and 
requirements discussions. Keeping in mind that running code is one of 
the main criteria for the IETF and the protocols are the ultimate output 
of our WG.

Therefore, please feel free to start working on more protocol and 
technical drafts.
When we meet in Yokohama or before when you read the various use cases 
and requirements, start thinking about how would an implementation look 
like. What would the protocols look like to fulfill these requirements.

All the best and see you soon in Yokohama.

Tobias & Roman (co-chairs)




--------------010907000801050006050509
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">Dear DOTS WG, <br>
      <br>
      it is great to see that so many first drafts have come in. <br>
      And we are very happy to see that the first versions of the use
      case, requirements and protocol drafts have been posted. <br>
      <br>
      We like to encourage people to start thinking and working on
      protocol drafts in parallel to the existing use case and requirements.
      <br>
      <br>
      We appreciate that protocol drafts are the answer to use cases and
      requirements. But equally they can help to inform the use case and
      requirements discussions. Keeping in mind that running code is one
      of the main criteria for the IETF and the protocols are the
      ultimate output of our WG. <br>
      <br>
      Therefore, please feel free to start working on more protocol and
      technical drafts. <br>
      When we meet in Yokohama or before when you read the various use
      cases and requirements, start thinking about how would an
      implementation look like. What would the protocols look like to
      fulfill these requirements. <br>
      <br>
      All the best and see you soon in Yokohama. <br>
      <br>
      Tobias &amp; Roman (co-chairs)<br>
      <br>
      <br>
      <br>
    </font>
  </body>
</html>

--------------010907000801050006050509--


From nobody Sun Oct 25 13:13:55 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B3D171B3123 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 13:13:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -93.465
X-Spam-Level: 
X-Spam-Status: No, score=-93.465 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, GB_ABOUTYOU=0.5, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dQ5tkZcWEbT3 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 13:13:53 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB2E11B3122 for <dots@ietf.org>; Sun, 25 Oct 2015 13:13:52 -0700 (PDT)
Received: from [192.168.178.26] (x590f7e4f.dyn.telefonica.de [89.15.126.79]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 5B39A62DD5; Sun, 25 Oct 2015 21:13:50 +0100 (CET)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=XedmrNTySoggRVLYJmdv2HoRWgJdX+vlm9VTsS86qZFEQ+ZMohT7s9nzI81TSaePaOWFC1pROTFJfPcyvUTCzbljG43XM3eM9y18EA8DAZbuLSLa4eXkEbClpujU2mQtNX00jvWXyvTDcR6WrDHaXnn2g+q+YFpwVU0jNpvDTho=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type:Content-Transfer-Encoding;
Message-ID: <562D37FD.2050801@gondrom.org>
Date: Sun, 25 Oct 2015 21:13:49 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: rdobbins@arbor.net
References: <561179CA.3020107@gondrom.org> <1EE67EAE-4EBB-4BC3-96D9-281EE2A40E83@arbor.net>
In-Reply-To: <1EE67EAE-4EBB-4BC3-96D9-281EE2A40E83@arbor.net>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/uJed_SQcCmRFrIVGGJxcA9zm39M>
Cc: rdd@cert.org, dots@ietf.org
Subject: Re: [Dots] Reminder on the charter of DOTS and that multiple scenarios are in scope
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Oct 2015 20:13:54 -0000

Dear Roland,

your concerns have been noted.

Please note that the chairs have spend significant time on re-reading 
all relevant emails, your previous comments, the charter text itself and 
discussions leading up to WG consensus on the charter. And as mentioned 
before, the chairs and the AD were unanimous in our understanding of the 
charter.

Furthermore, I note that you now have for a second time made statements 
that might give others the impression that you would claim to be the 
authoritative person as to the meaning of the charter text. E.g. in "As 
a WG participant who contributed to that specific wording in the 
charter, please allow me to clarify its intended meaning." or "...by the 
individual who contributed it to the DOTS WG charter."

To avoid misunderstanding from other WG members about your comments, let 
me explicitly state the following:
The charter is the result of IETF / WG consensus.
We are thankful for all contributions. However, the aspect that an 
individual contributed to the text does in no way give him/her 
interpretation authority as to its meaning. Nor would it allow him/her 
to interpret or shift existing WG consensus, based on what he/she thinks 
or had in mind. This is the role of the WG as a whole and the WG chairs 
listening to that WG consensus. And we ask contributors to please not 
assume nor assert towards others that your opinion would supersede that 
of other members of the WG based on such history.

We will be available for further explanation in Yokohama,
However, please understand the conclusion of the WG chairs and AD on the 
existing scope as written in Roman's email before.

Thank you and best regards, Tobias (WG co-chair)


Ps.: I will reply on draft specific comments separately.




On 24/10/15 06:39, Roland Dobbins wrote:
>
> [I apparently missed this message on 5Oct2015; apologies for the late 
> reply!]
>
> On 5 Oct 2015, at 2:11, Tobias Gondrom wrote:
>
>> "The aim of DDoS Open Threat Signaling (DOTS) is to develop a 
>> standards based approach for the realtime signaling of DDoS related 
>> telemetry and threat handling requests and data between elements 
>> concerned with DDoS attack detection, classification, traceback, and 
>> mitigation.")
>
> As a WG participant who contributed to that specific wording in the 
> charter, please allow me to clarify its intended meaning.
>
> The 'telemetry' part was not meant to imply that the DOTS WG should 
> take on the huge task of further redefining existing telemetry 
> standards such as IPFIX as a goal in and of itself. This is a much 
> bigger job with implications far beyond the realm of threat signaling.
>
> The intent was to ensure that we could potentially utilize existing 
> telemetry mechanisms for the purpose of signaling and communicating 
> threat handling requests, and to potentially explore the extension of 
> those standards, if necessary, in order to enhance their suitability 
> for the threat signaling and the communication of threat handling 
> requests, nothing more.  The emphasis was meant to be on the 
> 'signaling' and 'threat handling' parts, not the 'telemetry' parts.
>
> Very specifically, 'signaling of DDoS related telemetry' does not 
> imply 'redefinition of DDoS related telemetry'.
>
>> We should be careful to avoid individual attempts of re-interpretations
>
> The above is not in fact a re-interpretation; as the WG participant 
> who contributed the specific verbiage in question, it is a statement 
> of the literal meaning of the verbiage in question by the individual 
> who contributed it to the DOTS WG charter.
>
> See <http://www.ietf.org/mail-archive/web/dots/current/msg00131.html>.
>
>> based on company perspectives about what would be out-of-scope of the 
>> WG.
>
> To clarify, expressed views regarding the expansion of the scope of 
> the DOTS WG beyond threat signaling are wholly unrelated to company 
> perspectives.
>
> They are the expression of legitimate concerns by individual 
> contributors to the DOTS WG that by expanding the focus of the DOTS WG 
> beyond the realm of threat signaling, we are inadvertently embracing a 
> much larger task than establishing a standards-based mechanism for 
> threats-signaling and which has the potential to jeopardizes our 
> ability to focus on the completion of the DOTS WG goal of establishing 
> a standards-based mechanism within a relatively short timeframe.
>
> -----------------------------------
> Roland Dobbins <rdobbins@arbor.net>
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


From nobody Sun Oct 25 13:20:07 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 054861B3138 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 13:20:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -93.664
X-Spam-Level: 
X-Spam-Status: No, score=-93.664 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p2z0UtONWg1e for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 13:20:04 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F23681B3137 for <dots@ietf.org>; Sun, 25 Oct 2015 13:20:03 -0700 (PDT)
Received: from [192.168.178.26] (x590f7e4f.dyn.telefonica.de [89.15.126.79]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 8C21962DD5; Sun, 25 Oct 2015 21:20:01 +0100 (CET)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=wShl4j/4YjFwyJRwYkDKoVBJwP6AQE4LcahbkecvASRIdj3w/yd6tTvHlcJQrF+2pzXixpM9Z8Yom4yf9b6FYoasy0mKH4S8pn2Iq1V5QiOBJJsjQ7BW5ztr0WXPKJXmKvgU3KGPhH4lPRYcnjuZHIm22/QVApS8nFdQDwgZdt4=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type;
Message-ID: <562D3971.8040003@gondrom.org>
Date: Sun, 25 Oct 2015 21:20:01 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: frank.xialiang@huawei.com, rdobbins@arbor.net, dots@ietf.org
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com>
In-Reply-To: <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------090007050901090304030304"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/Pevo9J8RKlciRFh4TfKkipTEorM>
Cc: rdd@cert.org
Subject: Re: [Dots] =?utf-8?b?562U5aSNOiAgTmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZv?= =?utf-8?q?r_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Oct 2015 20:20:06 -0000

This is a multi-part message in MIME format.
--------------090007050901090304030304
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Frank,

thank you for your explanations.
It could be helpful to explain in more detail in the next version of the 
draft, e.g. in the introduction section, a bit more about the context of 
the draft in relation to threat signaling. People attending the BOFs and 
pre-BOF discussion have the context, but it may be less clear for a new 
reader.

Best regards, Tobias


On 19/10/15 05:33, Xialiang (Frank) wrote:
> Hi Roland and all,
> See my clarifications:
>
> -----邮件原件-----
> 发件人: Dots [mailto:dots-bounces@ietf.org] 代表 Roland Dobbins
> 发送时间: 2015年10月19日 11:19
> 收件人: dots
> 抄送: Roman D. Danyliw; Tobias Gondrom
> 主题: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
>
>
> On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:
>
>> May I request for a 5 or 10 minutes time slot for presenting the
>> following draft, as an input for the discussion about attack telemetry
>> information?
>   From the DOTS WG charter:
>
>     The WG will, where appropriate, reuse or extend existing standard
>     protocols and mechanisms (for example, IPFIX and its associated
>     templating and extension mechanisms).
>
> This language in the DOTS WG charter is not intended to suggest a general extension of any existing standards such as IPFIX; rather, it is intended to note that should an existing standard may be desirable for use within the context of threat signaling, the DOTS WG may request an extension of said standard to support the DOTS mission of standards-based threat signaling.
>
> draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is wholly unconcerned with threat signaling.
>
> [Frank]: It's related with what information about threat or attack can be used for DOTS threat signaling. Do you mean the attack telemetry information is not the goal of DOTS?
>
>   From the DOTS WG charter:
>
>     Any modification of or extension to existing protocols must be in close coordination with the working
>     groups responsible for the protocol being modified, and may be done in this working group after agreement
>     with all the relevant WGs and responsible Area Directors.
>
> The above criteria from the DOTS WG charter have not been fulfilled with regards to any proposed extension of IPFIX.
>
> It is respectfully suggested to the chairs that this draft (as in its previous iteration) is more suited for the (currently Concluded) IPFIX WG, as it is not directly related to the potential use of IPFIX for threat signaling, but is more of a proposed general extension of IPFIX.
>
> [Frank]: From my perspective, this draft is related to the potential use of IPFIX for the attack telemetry.
>
>
> As such, its authors would more profitably direct their efforts in this regard by petitioning for a reopening of the IPFIX WG.
>
> -----------------------------------
> Roland Dobbins <rdobbins@arbor.net>
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--------------090007050901090304030304
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">Hi Frank, <br>
      <br>
      thank you for your explanations. <br>
      It could be helpful to explain in more detail in the next version
      of the draft, e.g. in the introduction section, a bit more about
      the context of the draft in relation to threat signaling. People
      attending the BOFs and pre-BOF discussion have the context, but it
      may be less clear for a new reader. <br>
      <br>
      Best regards, Tobias<br>
       </font><br>
    <br>
    <div class="moz-cite-prefix">On 19/10/15 05:33, Xialiang (Frank)
      wrote:<br>
    </div>
    <blockquote
cite="mid:C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com"
      type="cite">
      <pre wrap="">Hi Roland and all,
See my clarifications:

-----邮件原件-----
发件人: Dots [<a class="moz-txt-link-freetext" href="mailto:dots-bounces@ietf.org">mailto:dots-bounces@ietf.org</a>] 代表 Roland Dobbins
发送时间: 2015年10月19日 11:19
收件人: dots
抄送: Roman D. Danyliw; Tobias Gondrom
主题: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt


On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:

</pre>
      <blockquote type="cite">
        <pre wrap="">May I request for a 5 or 10 minutes time slot for presenting the 
following draft, as an input for the discussion about attack telemetry 
information?
</pre>
      </blockquote>
      <pre wrap="">
 From the DOTS WG charter:

   The WG will, where appropriate, reuse or extend existing standard
   protocols and mechanisms (for example, IPFIX and its associated
   templating and extension mechanisms).

This language in the DOTS WG charter is not intended to suggest a general extension of any existing standards such as IPFIX; rather, it is intended to note that should an existing standard may be desirable for use within the context of threat signaling, the DOTS WG may request an extension of said standard to support the DOTS mission of standards-based threat signaling.

draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is wholly unconcerned with threat signaling.

[Frank]: It's related with what information about threat or attack can be used for DOTS threat signaling. Do you mean the attack telemetry information is not the goal of DOTS?

 From the DOTS WG charter:

   Any modification of or extension to existing protocols must be in close coordination with the working
   groups responsible for the protocol being modified, and may be done in this working group after agreement
   with all the relevant WGs and responsible Area Directors.

The above criteria from the DOTS WG charter have not been fulfilled with regards to any proposed extension of IPFIX.

It is respectfully suggested to the chairs that this draft (as in its previous iteration) is more suited for the (currently Concluded) IPFIX WG, as it is not directly related to the potential use of IPFIX for threat signaling, but is more of a proposed general extension of IPFIX.  

[Frank]: From my perspective, this draft is related to the potential use of IPFIX for the attack telemetry.


As such, its authors would more profitably direct their efforts in this regard by petitioning for a reopening of the IPFIX WG.

-----------------------------------
Roland Dobbins <a class="moz-txt-link-rfc2396E" href="mailto:rdobbins@arbor.net">&lt;rdobbins@arbor.net&gt;</a>

_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------090007050901090304030304--


From nobody Sun Oct 25 18:55:00 2015
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A0741B34C3 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 18:54:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.078
X-Spam-Level: **
X-Spam-Status: No, score=2.078 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CHARSET_FARAWAY_HEADER=3.2, CN_BODY_35=0.339, MIME_8BIT_HEADER=0.3, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vpKYUknAesdR for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 18:54:58 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2822D1A89F0 for <dots@ietf.org>; Sun, 25 Oct 2015 18:54:57 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml401-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BZG61994; Mon, 26 Oct 2015 01:54:55 +0000 (GMT)
Received: from SZXEMA412-HUB.china.huawei.com (10.82.72.71) by lhreml401-hub.china.huawei.com (10.201.5.240) with Microsoft SMTP Server (TLS) id 14.3.235.1; Mon, 26 Oct 2015 01:54:54 +0000
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.77]) by SZXEMA412-HUB.china.huawei.com ([10.82.72.71]) with mapi id 14.03.0235.001; Mon, 26 Oct 2015 09:54:45 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: "Teague, Nik" <nteague@verisign.com>, Roland Dobbins <rdobbins@arbor.net>
Thread-Topic: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
Thread-Index: AQHRChKBgy392uVC4EubFSU1bnOiOZ5yErmA//+MtgCAAIcqYIAB/t+AgATOp4CAAKHcAIAAPXwAgAM2s/A=
Date: Mon, 26 Oct 2015 01:54:44 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AE8F0BA@SZXEMA502-MBS.china.huawei.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <534A150D-7A41-40B5-A637-D1870BFB1926@arbor.net> <359EC4B99E040048A7131E0F4E113AFCD9534B3B@marathon>, <98F23B2C-7398-4449-99DF-66FA05D99FD2@arbor.net> <5DA95CE7-ED2D-495A-933E-D2BD107075DA@Verisign.com>
In-Reply-To: <5DA95CE7-ED2D-495A-933E-D2BD107075DA@Verisign.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.135.43.91]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/yNnqWqh5t6IE43QIVF7qeEdnpI4>
Cc: "Roman D. Danyliw" <rdd@cert.org>, dots <dots@ietf.org>
Subject: [Dots] =?gb2312?b?tPC4tDogIE5ldyBWZXJzaW9uIE5vdGlmaWNhdGlvbiBm?= =?gb2312?b?b3IgZHJhZnQtZnUtZG90cy1pcGZpeC1leHRlbnNpb24tMDAudHh0?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 01:54:59 -0000

SGkgTmlrLA0KSSB0b3RhbGx5IHVuZGVyc3RhbmQgYW5kIGFncmVlIHdpdGggeW91ciBjb21tZW50
cy4NCklNSE8sIHJlYWwgdXNlIGNhc2VzIGRyaXZlIHRoZSByaWdodCBkaXJlY3Rpb24sIGFuZCBp
dHMgdmFsdWUgaXMgbm90IHJlbGF0ZWQgd2l0aCB0aGUgcHJvdG9jb2wuDQoNCg0KQi5SLg0KRnJh
bmsNCg0KLS0tLS3Tyrz+1K28/i0tLS0tDQq3orz+yMs6IERvdHMgW21haWx0bzpkb3RzLWJvdW5j
ZXNAaWV0Zi5vcmddILT6se0gVGVhZ3VlLCBOaWsNCreiy83KsbzkOiAyMDE1xOoxMNTCMjTI1SAx
NjozNQ0KytW8/sjLOiBSb2xhbmQgRG9iYmlucw0Ks63LzTogUm9tYW4gRC4gRGFueWxpdzsgZG90
cw0K1vfM4jogUmU6IFtEb3RzXSBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24gZm9yIGRyYWZ0LWZ1
LWRvdHMtaXBmaXgtZXh0ZW5zaW9uLTAwLnR4dA0KDQpPbiAyNCBPY3QgMjAxNSwgYXQgMDU6NTUs
IFJvbGFuZCBEb2JiaW5zIDxyZG9iYmluc0BhcmJvci5uZXQ+IHdyb3RlOg0KDQo+PiBPbiAyNCBP
Y3QgMjAxNSwgYXQgMjoxNSwgUm9tYW4gRC4gRGFueWxpdyB3cm90ZToNCj4+IA0KPj4gSWYgdGhl
cmUgYXJlIGFueSBxdWVzdGlvbnMgb3IgY29uY2VybnMsIHBsZWFzZSBsZXQgdXMga25vdyBhbmQg
d2Ugd2lsbCBiZSBoYXBweSB0byBoZWxwLg0KDQpNeSAyYw0KDQpBIGxvdCBvZiB0aGlzIGRpc2N1
c3Npb24gaXMgc29tZXdoYXQgZGlzdHJhY3RpbmcgZnJvbSB0aGUgZmFjdCB0aGF0IHVzZSBjYXNl
cyB3aWxsIGRyaXZlIHJlcXVpcmVtZW50cyBhbmQgaW4gdHVybiBkcml2ZSB0aGUgZW5kIHJlc3Vs
dC4uLiBpZiB0aGF0J3MgSVBGSVggb3IgcGlnZW9ucyBpcyBub3QgYSBkaXJlY3QgY29uY2VybiBh
dG0uDQoNClRoYW5rcywNCg0KLU5paw0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX18NCkRvdHMgbWFpbGluZyBsaXN0DQpEb3RzQGlldGYub3JnDQpodHRwczov
L3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2RvdHMNCg==


From nobody Sun Oct 25 19:04:21 2015
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 862FC1B34E3 for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 19:04:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.91
X-Spam-Level: 
X-Spam-Status: No, score=-3.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w6X4i2cX3n_i for <dots@ietfa.amsl.com>; Sun, 25 Oct 2015 19:04:16 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A100B1B34E2 for <dots@ietf.org>; Sun, 25 Oct 2015 19:04:14 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml405-hub.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id CDA02486; Mon, 26 Oct 2015 02:04:13 +0000 (GMT)
Received: from SZXEMA411-HUB.china.huawei.com (10.82.72.70) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.235.1; Mon, 26 Oct 2015 02:04:12 +0000
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.77]) by szxema411-hub.china.huawei.com ([10.82.72.70]) with mapi id 14.03.0235.001; Mon, 26 Oct 2015 10:04:04 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: Tobias Gondrom <tobias.gondrom@gondrom.org>, "rdd@cert.org" <rdd@cert.org>
Thread-Topic: =?utf-8?B?W0RvdHNdIOetlOWkjTogIE5ldyBWZXJzaW9uIE5vdGlmaWNhdGlvbiBmb3Ig?= =?utf-8?Q?draft-fu-dots-ipfix-extension-00.txt?=
Thread-Index: AQHRD2KQuzpFUhQNIkav9LedezcLtp58+CHg
Date: Mon, 26 Oct 2015 02:04:03 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AE8F0D7@SZXEMA502-MBS.china.huawei.com>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <562D3971.8040003@gondrom.org>
In-Reply-To: <562D3971.8040003@gondrom.org>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.135.43.91]
Content-Type: multipart/alternative; boundary="_000_C02846B1344F344EB4FAA6FA7AF481F12AE8F0D7SZXEMA502MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/6jcpIQnwg0PSLBLRJao6Doc_Jv4>
Cc: "rdobbins@arbor.net" <rdobbins@arbor.net>, "dots@ietf.org" <dots@ietf.org>
Subject: [Dots] =?utf-8?b?562U5aSNOiAg562U5aSNOiAgTmV3IFZlcnNpb24gTm90aWZp?= =?utf-8?q?cation_for_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 02:04:19 -0000

--_000_C02846B1344F344EB4FAA6FA7AF481F12AE8F0D7SZXEMA502MBSchi_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

SGkgY2hhaXJzLA0KWW91IGFyZSByaWdodCEgSSB3aWxsIGluY2x1ZGUgbW9yZSBleHBsYW5hdGlv
bnMgaW4gdGhlIG5leHQgdmVyc2lvbiBvZiB0aGUgZHJhZnQgdG8gY2xhcmlmeSBpdHMgcmVsYXRp
b24gd2l0aCB0aHJlYXQgc2lnbmFsaW5nIGFuZCB0aGUgcmVhc29uIHdoeSBpdCBpcyB1c2VmdWwg
aW4gRE9UUy4NCg0KVGhhbmtzIGZvciB5b3VyIGNvbmNlcm4uDQoNCkIuUi4NCkZyYW5rDQoNCuWP
keS7tuS6ujogVG9iaWFzIEdvbmRyb20gW21haWx0bzp0b2JpYXMuZ29uZHJvbUBnb25kcm9tLm9y
Z10NCuWPkemAgeaXtumXtDogMjAxNeW5tDEw5pyIMjbml6UgNDoyMA0K5pS25Lu25Lq6OiBYaWFs
aWFuZyAoRnJhbmspOyByZG9iYmluc0BhcmJvci5uZXQ7IGRvdHNAaWV0Zi5vcmcNCuaKhOmAgTog
cmRkQGNlcnQub3JnDQrkuLvpopg6IFJlOiBbRG90c10g562U5aSNOiBOZXcgVmVyc2lvbiBOb3Rp
ZmljYXRpb24gZm9yIGRyYWZ0LWZ1LWRvdHMtaXBmaXgtZXh0ZW5zaW9uLTAwLnR4dA0KDQpIaSBG
cmFuaywNCg0KdGhhbmsgeW91IGZvciB5b3VyIGV4cGxhbmF0aW9ucy4NCkl0IGNvdWxkIGJlIGhl
bHBmdWwgdG8gZXhwbGFpbiBpbiBtb3JlIGRldGFpbCBpbiB0aGUgbmV4dCB2ZXJzaW9uIG9mIHRo
ZSBkcmFmdCwgZS5nLiBpbiB0aGUgaW50cm9kdWN0aW9uIHNlY3Rpb24sIGEgYml0IG1vcmUgYWJv
dXQgdGhlIGNvbnRleHQgb2YgdGhlIGRyYWZ0IGluIHJlbGF0aW9uIHRvIHRocmVhdCBzaWduYWxp
bmcuIFBlb3BsZSBhdHRlbmRpbmcgdGhlIEJPRnMgYW5kIHByZS1CT0YgZGlzY3Vzc2lvbiBoYXZl
IHRoZSBjb250ZXh0LCBidXQgaXQgbWF5IGJlIGxlc3MgY2xlYXIgZm9yIGEgbmV3IHJlYWRlci4N
Cg0KQmVzdCByZWdhcmRzLCBUb2JpYXMNCg0KT24gMTkvMTAvMTUgMDU6MzMsIFhpYWxpYW5nIChG
cmFuaykgd3JvdGU6DQoNCkhpIFJvbGFuZCBhbmQgYWxsLA0KDQpTZWUgbXkgY2xhcmlmaWNhdGlv
bnM6DQoNCg0KDQotLS0tLemCruS7tuWOn+S7ti0tLS0tDQoNCuWPkeS7tuS6ujogRG90cyBbbWFp
bHRvOmRvdHMtYm91bmNlc0BpZXRmLm9yZ10g5Luj6KGoIFJvbGFuZCBEb2JiaW5zDQoNCuWPkemA
geaXtumXtDogMjAxNeW5tDEw5pyIMTnml6UgMTE6MTkNCg0K5pS25Lu25Lq6OiBkb3RzDQoNCuaK
hOmAgTogUm9tYW4gRC4gRGFueWxpdzsgVG9iaWFzIEdvbmRyb20NCg0K5Li76aKYOiBSZTogW0Rv
dHNdIE5ldyBWZXJzaW9uIE5vdGlmaWNhdGlvbiBmb3IgZHJhZnQtZnUtZG90cy1pcGZpeC1leHRl
bnNpb24tMDAudHh0DQoNCg0KDQoNCg0KT24gMTkgT2N0IDIwMTUsIGF0IDk6MTQsIFhpYWxpYW5n
IChGcmFuaykgd3JvdGU6DQoNCg0KDQpNYXkgSSByZXF1ZXN0IGZvciBhIDUgb3IgMTAgbWludXRl
cyB0aW1lIHNsb3QgZm9yIHByZXNlbnRpbmcgdGhlDQoNCmZvbGxvd2luZyBkcmFmdCwgYXMgYW4g
aW5wdXQgZm9yIHRoZSBkaXNjdXNzaW9uIGFib3V0IGF0dGFjayB0ZWxlbWV0cnkNCg0KaW5mb3Jt
YXRpb24/DQoNCg0KDQogRnJvbSB0aGUgRE9UUyBXRyBjaGFydGVyOg0KDQoNCg0KICAgVGhlIFdH
IHdpbGwsIHdoZXJlIGFwcHJvcHJpYXRlLCByZXVzZSBvciBleHRlbmQgZXhpc3Rpbmcgc3RhbmRh
cmQNCg0KICAgcHJvdG9jb2xzIGFuZCBtZWNoYW5pc21zIChmb3IgZXhhbXBsZSwgSVBGSVggYW5k
IGl0cyBhc3NvY2lhdGVkDQoNCiAgIHRlbXBsYXRpbmcgYW5kIGV4dGVuc2lvbiBtZWNoYW5pc21z
KS4NCg0KDQoNClRoaXMgbGFuZ3VhZ2UgaW4gdGhlIERPVFMgV0cgY2hhcnRlciBpcyBub3QgaW50
ZW5kZWQgdG8gc3VnZ2VzdCBhIGdlbmVyYWwgZXh0ZW5zaW9uIG9mIGFueSBleGlzdGluZyBzdGFu
ZGFyZHMgc3VjaCBhcyBJUEZJWDsgcmF0aGVyLCBpdCBpcyBpbnRlbmRlZCB0byBub3RlIHRoYXQg
c2hvdWxkIGFuIGV4aXN0aW5nIHN0YW5kYXJkIG1heSBiZSBkZXNpcmFibGUgZm9yIHVzZSB3aXRo
aW4gdGhlIGNvbnRleHQgb2YgdGhyZWF0IHNpZ25hbGluZywgdGhlIERPVFMgV0cgbWF5IHJlcXVl
c3QgYW4gZXh0ZW5zaW9uIG9mIHNhaWQgc3RhbmRhcmQgdG8gc3VwcG9ydCB0aGUgRE9UUyBtaXNz
aW9uIG9mIHN0YW5kYXJkcy1iYXNlZCB0aHJlYXQgc2lnbmFsaW5nLg0KDQoNCg0KZHJhZnQtZnUt
ZG90cy1pcGZpeC1leHRlbnNpb24tMDAgZG9lcyBub3QgbWVldCB0aGVzZSBjcml0ZXJpYTsgaXQg
aXMgd2hvbGx5IHVuY29uY2VybmVkIHdpdGggdGhyZWF0IHNpZ25hbGluZy4NCg0KDQoNCltGcmFu
a106IEl0J3MgcmVsYXRlZCB3aXRoIHdoYXQgaW5mb3JtYXRpb24gYWJvdXQgdGhyZWF0IG9yIGF0
dGFjayBjYW4gYmUgdXNlZCBmb3IgRE9UUyB0aHJlYXQgc2lnbmFsaW5nLiBEbyB5b3UgbWVhbiB0
aGUgYXR0YWNrIHRlbGVtZXRyeSBpbmZvcm1hdGlvbiBpcyBub3QgdGhlIGdvYWwgb2YgRE9UUz8N
Cg0KDQoNCiBGcm9tIHRoZSBET1RTIFdHIGNoYXJ0ZXI6DQoNCg0KDQogICBBbnkgbW9kaWZpY2F0
aW9uIG9mIG9yIGV4dGVuc2lvbiB0byBleGlzdGluZyBwcm90b2NvbHMgbXVzdCBiZSBpbiBjbG9z
ZSBjb29yZGluYXRpb24gd2l0aCB0aGUgd29ya2luZw0KDQogICBncm91cHMgcmVzcG9uc2libGUg
Zm9yIHRoZSBwcm90b2NvbCBiZWluZyBtb2RpZmllZCwgYW5kIG1heSBiZSBkb25lIGluIHRoaXMg
d29ya2luZyBncm91cCBhZnRlciBhZ3JlZW1lbnQNCg0KICAgd2l0aCBhbGwgdGhlIHJlbGV2YW50
IFdHcyBhbmQgcmVzcG9uc2libGUgQXJlYSBEaXJlY3RvcnMuDQoNCg0KDQpUaGUgYWJvdmUgY3Jp
dGVyaWEgZnJvbSB0aGUgRE9UUyBXRyBjaGFydGVyIGhhdmUgbm90IGJlZW4gZnVsZmlsbGVkIHdp
dGggcmVnYXJkcyB0byBhbnkgcHJvcG9zZWQgZXh0ZW5zaW9uIG9mIElQRklYLg0KDQoNCg0KSXQg
aXMgcmVzcGVjdGZ1bGx5IHN1Z2dlc3RlZCB0byB0aGUgY2hhaXJzIHRoYXQgdGhpcyBkcmFmdCAo
YXMgaW4gaXRzIHByZXZpb3VzIGl0ZXJhdGlvbikgaXMgbW9yZSBzdWl0ZWQgZm9yIHRoZSAoY3Vy
cmVudGx5IENvbmNsdWRlZCkgSVBGSVggV0csIGFzIGl0IGlzIG5vdCBkaXJlY3RseSByZWxhdGVk
IHRvIHRoZSBwb3RlbnRpYWwgdXNlIG9mIElQRklYIGZvciB0aHJlYXQgc2lnbmFsaW5nLCBidXQg
aXMgbW9yZSBvZiBhIHByb3Bvc2VkIGdlbmVyYWwgZXh0ZW5zaW9uIG9mIElQRklYLg0KDQoNCg0K
W0ZyYW5rXTogRnJvbSBteSBwZXJzcGVjdGl2ZSwgdGhpcyBkcmFmdCBpcyByZWxhdGVkIHRvIHRo
ZSBwb3RlbnRpYWwgdXNlIG9mIElQRklYIGZvciB0aGUgYXR0YWNrIHRlbGVtZXRyeS4NCg0KDQoN
Cg0KDQpBcyBzdWNoLCBpdHMgYXV0aG9ycyB3b3VsZCBtb3JlIHByb2ZpdGFibHkgZGlyZWN0IHRo
ZWlyIGVmZm9ydHMgaW4gdGhpcyByZWdhcmQgYnkgcGV0aXRpb25pbmcgZm9yIGEgcmVvcGVuaW5n
IG9mIHRoZSBJUEZJWCBXRy4NCg0KDQoNCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tDQoNClJvbGFuZCBEb2JiaW5zIDxyZG9iYmluc0BhcmJvci5uZXQ+PG1haWx0bzpyZG9iYmlu
c0BhcmJvci5uZXQ+DQoNCg0KDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fXw0KDQpEb3RzIG1haWxpbmcgbGlzdA0KDQpEb3RzQGlldGYub3JnPG1haWx0bzpE
b3RzQGlldGYub3JnPg0KDQpodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2Rv
dHMNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18NCg0K
RG90cyBtYWlsaW5nIGxpc3QNCg0KRG90c0BpZXRmLm9yZzxtYWlsdG86RG90c0BpZXRmLm9yZz4N
Cg0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9kb3RzDQoNCg==

--_000_C02846B1344F344EB4FAA6FA7AF481F12AE8F0D7SZXEMA502MBSchi_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTIgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
5a6L5L2TOw0KCXBhbm9zZS0xOjIgMSA2IDAgMyAxIDEgMSAxIDE7fQ0KQGZvbnQtZmFjZQ0KCXtm
b250LWZhbWlseToiQ2FtYnJpYSBNYXRoIjsNCglwYW5vc2UtMToyIDQgNSAzIDUgNCA2IDMgMiA0
O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Q2FsaWJyaTsNCglwYW5vc2UtMToyIDE1IDUg
MiAyIDIgNCAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OiJcQOWui+S9kyI7DQoJ
cGFub3NlLTE6MiAxIDYgMCAzIDEgMSAxIDEgMTt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0K
cC5Nc29Ob3JtYWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGNtOw0K
CW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5
OuWui+S9kzsNCgljb2xvcjpibGFjazt9DQphOmxpbmssIHNwYW4uTXNvSHlwZXJsaW5rDQoJe21z
by1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpibHVlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRl
cmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFuLk1zb0h5cGVybGlua0ZvbGxvd2VkDQoJe21zby1zdHls
ZS1wcmlvcml0eTo5OTsNCgljb2xvcjpwdXJwbGU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGlu
ZTt9DQpwcmUNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1M
IOmihOiuvuagvOW8jyBDaGFyIjsNCgltYXJnaW46MGNtOw0KCW1hcmdpbi1ib3R0b206LjAwMDFw
dDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5OuWui+S9kzsNCgljb2xvcjpibGFj
azt9DQpwLk1zb0FjZXRhdGUsIGxpLk1zb0FjZXRhdGUsIGRpdi5Nc29BY2V0YXRlDQoJe21zby1z
dHlsZS1wcmlvcml0eTo5OTsNCgltc28tc3R5bGUtbGluazoi5om55rOo5qGG5paH5pysIENoYXIi
Ow0KCW1hcmdpbjowY207DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZTo5LjBw
dDsNCglmb250LWZhbWlseTrlrovkvZM7DQoJY29sb3I6YmxhY2s7fQ0Kc3Bhbi5IVE1MQ2hhcg0K
CXttc28tc3R5bGUtbmFtZToiSFRNTCDpooTorr7moLzlvI8gQ2hhciI7DQoJbXNvLXN0eWxlLXBy
aW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJIVE1MIOmihOiuvuagvOW8jyI7DQoJZm9udC1m
YW1pbHk6IkNvdXJpZXIgTmV3IjsNCgljb2xvcjpibGFjazt9DQpzcGFuLkNoYXINCgl7bXNvLXN0
eWxlLW5hbWU6IuaJueazqOahhuaWh+acrCBDaGFyIjsNCgltc28tc3R5bGUtcHJpb3JpdHk6OTk7
DQoJbXNvLXN0eWxlLWxpbms65om55rOo5qGG5paH5pysOw0KCWZvbnQtZmFtaWx5OuWui+S9kzsN
Cgljb2xvcjpibGFjazt9DQpzcGFuLkVtYWlsU3R5bGUyMQ0KCXttc28tc3R5bGUtdHlwZTpwZXJz
b25hbC1yZXBseTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsInNhbnMtc2VyaWYiOw0KCWNvbG9y
OiMxRjQ5N0Q7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxlLXR5cGU6ZXhwb3J0LW9ubHk7
DQoJZm9udC1zaXplOjEwLjBwdDt9DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo2MTIuMHB0
IDc5Mi4wcHQ7DQoJbWFyZ2luOjcyLjBwdCA5MC4wcHQgNzIuMHB0IDkwLjBwdDt9DQpkaXYuV29y
ZFNlY3Rpb24xDQoJe3BhZ2U6V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+PCEtLVtpZiBndGUg
bXNvIDldPjx4bWw+DQo8bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJlZGl0IiBzcGlkbWF4PSIxMDI2
IiAvPg0KPC94bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8bzpzaGFw
ZWxheW91dCB2OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0iZWRpdCIgZGF0YT0iMSIgLz4N
CjwvbzpzaGFwZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwvaGVhZD4NCjxib2R5IGJnY29s
b3I9IndoaXRlIiBsYW5nPSJaSC1DTiIgbGluaz0iYmx1ZSIgdmxpbms9InB1cnBsZSI+DQo8ZGl2
IGNsYXNzPSJXb3JkU2VjdGlvbjEiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0i
RU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkm
cXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5IaSBjaGFpcnMsPG86
cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4t
VVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj5Zb3UgYXJlIHJpZ2h0ISBJ
IHdpbGwgaW5jbHVkZSBtb3JlIGV4cGxhbmF0aW9ucyBpbiB0aGUgbmV4dCB2ZXJzaW9uIG9mIHRo
ZSBkcmFmdCB0byBjbGFyaWZ5IGl0cyByZWxhdGlvbiB3aXRoIHRocmVhdCBzaWduYWxpbmcgYW5k
IHRoZSByZWFzb24gd2h5DQogaXQgaXMgdXNlZnVsIGluIERPVFMuPG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250
LXNpemU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90Oztjb2xvcjojMUY0OTdEIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtc2l6ZTox
MC41cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7O2NvbG9yOiMxRjQ5N0QiPlRoYW5rcyBmb3IgeW91ciBjb25jZXJuLjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0i
Zm9udC1zaXplOjEwLjVwdDtmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3Nh
bnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFGNDk3RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9w
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNp
emU6MTAuNXB0O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90Oztjb2xvcjojMUY0OTdEIj5CLlIuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuNXB0
O2ZvbnQtZmFtaWx5OiZxdW90O0NhbGlicmkmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90Oztj
b2xvcjojMUY0OTdEIj5GcmFuazxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjVwdDtmb250LWZh
bWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDs7Y29sb3I6IzFG
NDk3RCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRpdj4NCjxkaXYgc3R5bGU9ImJv
cmRlcjpub25lO2JvcmRlci10b3A6c29saWQgI0I1QzRERiAxLjBwdDtwYWRkaW5nOjMuMHB0IDBj
bSAwY20gMGNtIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxiPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6MTAuMHB0O2NvbG9yOndpbmRvd3RleHQiPuWPkeS7tuS6ujxzcGFuIGxhbmc9IkVOLVVTIj46
PC9zcGFuPjwvc3Bhbj48L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2NvbG9yOndpbmRvd3RleHQiPiBUb2JpYXMgR29uZHJvbSBbbWFpbHRvOnRvYmlhcy5nb25k
cm9tQGdvbmRyb20ub3JnXQ0KPGJyPg0KPC9zcGFuPjxiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
MTAuMHB0O2NvbG9yOndpbmRvd3RleHQiPuWPkemAgeaXtumXtDxzcGFuIGxhbmc9IkVOLVVTIj46
PC9zcGFuPjwvc3Bhbj48L2I+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAu
MHB0O2NvbG9yOndpbmRvd3RleHQiPiAyMDE1PC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
MTAuMHB0O2NvbG9yOndpbmRvd3RleHQiPuW5tDxzcGFuIGxhbmc9IkVOLVVTIj4xMDwvc3Bhbj7m
nIg8c3BhbiBsYW5nPSJFTi1VUyI+MjY8L3NwYW4+5pelPHNwYW4gbGFuZz0iRU4tVVMiPg0KIDQ6
MjA8YnI+DQo8L3NwYW4+PGI+5pS25Lu25Lq6PHNwYW4gbGFuZz0iRU4tVVMiPjo8L3NwYW4+PC9i
PjxzcGFuIGxhbmc9IkVOLVVTIj4gWGlhbGlhbmcgKEZyYW5rKTsgcmRvYmJpbnNAYXJib3IubmV0
OyBkb3RzQGlldGYub3JnPGJyPg0KPC9zcGFuPjxiPuaKhOmAgTxzcGFuIGxhbmc9IkVOLVVTIj46
PC9zcGFuPjwvYj48c3BhbiBsYW5nPSJFTi1VUyI+IHJkZEBjZXJ0Lm9yZzxicj4NCjwvc3Bhbj48
Yj7kuLvpopg8c3BhbiBsYW5nPSJFTi1VUyI+Ojwvc3Bhbj48L2I+PHNwYW4gbGFuZz0iRU4tVVMi
PiBSZTogW0RvdHNdIDwvc3Bhbj4NCuetlOWkjTxzcGFuIGxhbmc9IkVOLVVTIj46IE5ldyBWZXJz
aW9uIE5vdGlmaWNhdGlvbiBmb3IgZHJhZnQtZnUtZG90cy1pcGZpeC1leHRlbnNpb24tMDAudHh0
PG86cD48L286cD48L3NwYW4+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9w
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48c3Bh
biBsYW5nPSJFTi1VUyIgc3R5bGU9ImZvbnQtZmFtaWx5OiZxdW90O0FyaWFsJnF1b3Q7LCZxdW90
O3NhbnMtc2VyaWYmcXVvdDsiPkhpIEZyYW5rLA0KPGJyPg0KPGJyPg0KdGhhbmsgeW91IGZvciB5
b3VyIGV4cGxhbmF0aW9ucy4gPGJyPg0KSXQgY291bGQgYmUgaGVscGZ1bCB0byBleHBsYWluIGlu
IG1vcmUgZGV0YWlsIGluIHRoZSBuZXh0IHZlcnNpb24gb2YgdGhlIGRyYWZ0LCBlLmcuIGluIHRo
ZSBpbnRyb2R1Y3Rpb24gc2VjdGlvbiwgYSBiaXQgbW9yZSBhYm91dCB0aGUgY29udGV4dCBvZiB0
aGUgZHJhZnQgaW4gcmVsYXRpb24gdG8gdGhyZWF0IHNpZ25hbGluZy4gUGVvcGxlIGF0dGVuZGlu
ZyB0aGUgQk9GcyBhbmQgcHJlLUJPRiBkaXNjdXNzaW9uIGhhdmUgdGhlIGNvbnRleHQsIGJ1dA0K
IGl0IG1heSBiZSBsZXNzIGNsZWFyIGZvciBhIG5ldyByZWFkZXIuIDxicj4NCjxicj4NCkJlc3Qg
cmVnYXJkcywgVG9iaWFzPGJyPg0KJm5ic3A7PC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpw
PjwvbzpwPjwvc3Bhbj48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFu
Zz0iRU4tVVMiPk9uIDE5LzEwLzE1IDA1OjMzLCBYaWFsaWFuZyAoRnJhbmspIHdyb3RlOjxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6
NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5IaSBS
b2xhbmQgYW5kIGFsbCw8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0i
RU4tVVMiPlNlZSBteSBjbGFyaWZpY2F0aW9uczo8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxw
cmU+PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+LS0tLS08L3NwYW4+6YKu5Lu25Y6f5Lu2PHNwYW4gbGFuZz0i
RU4tVVMiPi0tLS0tPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPuWPkeS7tuS6ujxzcGFu
IGxhbmc9IkVOLVVTIj46IERvdHMgWzxhIGhyZWY9Im1haWx0bzpkb3RzLWJvdW5jZXNAaWV0Zi5v
cmciPm1haWx0bzpkb3RzLWJvdW5jZXNAaWV0Zi5vcmc8L2E+XSA8L3NwYW4+5Luj6KGoPHNwYW4g
bGFuZz0iRU4tVVMiPiBSb2xhbmQgRG9iYmluczxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT7lj5HpgIHml7bpl7Q8c3BhbiBsYW5nPSJFTi1VUyI+OiAyMDE1PC9zcGFuPuW5tDxzcGFuIGxh
bmc9IkVOLVVTIj4xMDwvc3Bhbj7mnIg8c3BhbiBsYW5nPSJFTi1VUyI+MTk8L3NwYW4+5pelPHNw
YW4gbGFuZz0iRU4tVVMiPiAxMToxOTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT7mlLbk
u7bkuro8c3BhbiBsYW5nPSJFTi1VUyI+OiBkb3RzPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPuaKhOmAgTxzcGFuIGxhbmc9IkVOLVVTIj46IFJvbWFuIEQuIERhbnlsaXc7IFRvYmlhcyBH
b25kcm9tPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPuS4u+mimDxzcGFuIGxhbmc9IkVO
LVVTIj46IFJlOiBbRG90c10gTmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZvciBkcmFmdC1mdS1k
b3RzLWlwZml4LWV4dGVuc2lvbi0wMC50eHQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+
PHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj5PbiAxOSBPY3QgMjAxNSwgYXQgOToxNCwgWGlhbGlhbmcgKEZyYW5r
KSB3cm90ZTo8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcHJlPg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdp
bi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij5NYXkgSSByZXF1ZXN0IGZvciBhIDUgb3IgMTAgbWludXRlcyB0aW1lIHNsb3QgZm9yIHByZXNl
bnRpbmcgdGhlIDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1V
UyI+Zm9sbG93aW5nIGRyYWZ0LCBhcyBhbiBpbnB1dCBmb3IgdGhlIGRpc2N1c3Npb24gYWJvdXQg
YXR0YWNrIHRlbGVtZXRyeSA8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFu
Zz0iRU4tVVMiPmluZm9ybWF0aW9uPzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPC9ibG9ja3F1
b3RlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4gRnJvbSB0aGUgRE9UUyBXRyBjaGFydGVyOjxv
OnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJz
cDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4mbmJzcDsmbmJz
cDsgVGhlIFdHIHdpbGwsIHdoZXJlIGFwcHJvcHJpYXRlLCByZXVzZSBvciBleHRlbmQgZXhpc3Rp
bmcgc3RhbmRhcmQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4t
VVMiPiZuYnNwOyZuYnNwOyBwcm90b2NvbHMgYW5kIG1lY2hhbmlzbXMgKGZvciBleGFtcGxlLCBJ
UEZJWCBhbmQgaXRzIGFzc29jaWF0ZWQ8bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNw
YW4gbGFuZz0iRU4tVVMiPiZuYnNwOyZuYnNwOyB0ZW1wbGF0aW5nIGFuZCBleHRlbnNpb24gbWVj
aGFuaXNtcykuPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVT
Ij48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMi
PlRoaXMgbGFuZ3VhZ2UgaW4gdGhlIERPVFMgV0cgY2hhcnRlciBpcyBub3QgaW50ZW5kZWQgdG8g
c3VnZ2VzdCBhIGdlbmVyYWwgZXh0ZW5zaW9uIG9mIGFueSBleGlzdGluZyBzdGFuZGFyZHMgc3Vj
aCBhcyBJUEZJWDsgcmF0aGVyLCBpdCBpcyBpbnRlbmRlZCB0byBub3RlIHRoYXQgc2hvdWxkIGFu
IGV4aXN0aW5nIHN0YW5kYXJkIG1heSBiZSBkZXNpcmFibGUgZm9yIHVzZSB3aXRoaW4gdGhlIGNv
bnRleHQgb2YgdGhyZWF0IHNpZ25hbGluZywgdGhlIERPVFMgV0cgbWF5IHJlcXVlc3QgYW4gZXh0
ZW5zaW9uIG9mIHNhaWQgc3RhbmRhcmQgdG8gc3VwcG9ydCB0aGUgRE9UUyBtaXNzaW9uIG9mIHN0
YW5kYXJkcy1iYXNlZCB0aHJlYXQgc2lnbmFsaW5nLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5kcmFmdC1mdS1kb3RzLWlwZml4LWV4dGVuc2lvbi0wMCBk
b2VzIG5vdCBtZWV0IHRoZXNlIGNyaXRlcmlhOyBpdCBpcyB3aG9sbHkgdW5jb25jZXJuZWQgd2l0
aCB0aHJlYXQgc2lnbmFsaW5nLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBs
YW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxh
bmc9IkVOLVVTIj5bRnJhbmtdOiBJdCdzIHJlbGF0ZWQgd2l0aCB3aGF0IGluZm9ybWF0aW9uIGFi
b3V0IHRocmVhdCBvciBhdHRhY2sgY2FuIGJlIHVzZWQgZm9yIERPVFMgdGhyZWF0IHNpZ25hbGlu
Zy4gRG8geW91IG1lYW4gdGhlIGF0dGFjayB0ZWxlbWV0cnkgaW5mb3JtYXRpb24gaXMgbm90IHRo
ZSBnb2FsIG9mIERPVFM/PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0i
RU4tVVMiPiBGcm9tIHRoZSBET1RTIFdHIGNoYXJ0ZXI6PG86cD48L286cD48L3NwYW4+PC9wcmU+
DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4N
CjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPiZuYnNwOyZuYnNwOyBBbnkgbW9kaWZpY2F0aW9uIG9m
IG9yIGV4dGVuc2lvbiB0byBleGlzdGluZyBwcm90b2NvbHMgbXVzdCBiZSBpbiBjbG9zZSBjb29y
ZGluYXRpb24gd2l0aCB0aGUgd29ya2luZzxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48
c3BhbiBsYW5nPSJFTi1VUyI+Jm5ic3A7Jm5ic3A7IGdyb3VwcyByZXNwb25zaWJsZSBmb3IgdGhl
IHByb3RvY29sIGJlaW5nIG1vZGlmaWVkLCBhbmQgbWF5IGJlIGRvbmUgaW4gdGhpcyB3b3JraW5n
IGdyb3VwIGFmdGVyIGFncmVlbWVudDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+Jm5ic3A7Jm5ic3A7IHdpdGggYWxsIHRoZSByZWxldmFudCBXR3MgYW5k
IHJlc3BvbnNpYmxlIEFyZWEgRGlyZWN0b3JzLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHBy
ZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJl
PjxzcGFuIGxhbmc9IkVOLVVTIj5UaGUgYWJvdmUgY3JpdGVyaWEgZnJvbSB0aGUgRE9UUyBXRyBj
aGFydGVyIGhhdmUgbm90IGJlZW4gZnVsZmlsbGVkIHdpdGggcmVnYXJkcyB0byBhbnkgcHJvcG9z
ZWQgZXh0ZW5zaW9uIG9mIElQRklYLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFu
IGxhbmc9IkVOLVVTIj5JdCBpcyByZXNwZWN0ZnVsbHkgc3VnZ2VzdGVkIHRvIHRoZSBjaGFpcnMg
dGhhdCB0aGlzIGRyYWZ0IChhcyBpbiBpdHMgcHJldmlvdXMgaXRlcmF0aW9uKSBpcyBtb3JlIHN1
aXRlZCBmb3IgdGhlIChjdXJyZW50bHkgQ29uY2x1ZGVkKSBJUEZJWCBXRywgYXMgaXQgaXMgbm90
IGRpcmVjdGx5IHJlbGF0ZWQgdG8gdGhlIHBvdGVudGlhbCB1c2Ugb2YgSVBGSVggZm9yIHRocmVh
dCBzaWduYWxpbmcsIGJ1dCBpcyBtb3JlIG9mIGEgcHJvcG9zZWQgZ2VuZXJhbCBleHRlbnNpb24g
b2YgSVBGSVguJm5ic3A7IDxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5n
PSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9
IkVOLVVTIj5bRnJhbmtdOiBGcm9tIG15IHBlcnNwZWN0aXZlLCB0aGlzIGRyYWZ0IGlzIHJlbGF0
ZWQgdG8gdGhlIHBvdGVudGlhbCB1c2Ugb2YgSVBGSVggZm9yIHRoZSBhdHRhY2sgdGVsZW1ldHJ5
LjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86cD4m
bmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZu
YnNwOzwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPkFzIHN1Y2gs
IGl0cyBhdXRob3JzIHdvdWxkIG1vcmUgcHJvZml0YWJseSBkaXJlY3QgdGhlaXIgZWZmb3J0cyBp
biB0aGlzIHJlZ2FyZCBieSBwZXRpdGlvbmluZyBmb3IgYSByZW9wZW5pbmcgb2YgdGhlIElQRklY
IFdHLjxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PG86
cD4mbmJzcDs8L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj4tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLTxvOnA+PC9vOnA+PC9zcGFuPjwvcHJlPg0K
PHByZT48c3BhbiBsYW5nPSJFTi1VUyI+Um9sYW5kIERvYmJpbnMgPGEgaHJlZj0ibWFpbHRvOnJk
b2JiaW5zQGFyYm9yLm5ldCI+Jmx0O3Jkb2JiaW5zQGFyYm9yLm5ldCZndDs8L2E+PG86cD48L286
cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpw
Pjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPl9fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8
cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5Eb3RzIG1haWxpbmcgbGlzdDxvOnA+PC9vOnA+PC9zcGFu
PjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PGEgaHJlZj0ibWFpbHRvOkRvdHNAaWV0
Zi5vcmciPkRvdHNAaWV0Zi5vcmc8L2E+PG86cD48L286cD48L3NwYW4+PC9wcmU+DQo8cHJlPjxz
cGFuIGxhbmc9IkVOLVVTIj48YSBocmVmPSJodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xp
c3RpbmZvL2RvdHMiPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vZG90czwv
YT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjxwcmU+PHNwYW4gbGFuZz0iRU4tVVMiPl9fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPG86cD48L286cD48L3Nw
YW4+PC9wcmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj5Eb3RzIG1haWxpbmcgbGlzdDxvOnA+
PC9vOnA+PC9zcGFuPjwvcHJlPg0KPHByZT48c3BhbiBsYW5nPSJFTi1VUyI+PGEgaHJlZj0ibWFp
bHRvOkRvdHNAaWV0Zi5vcmciPkRvdHNAaWV0Zi5vcmc8L2E+PG86cD48L286cD48L3NwYW4+PC9w
cmU+DQo8cHJlPjxzcGFuIGxhbmc9IkVOLVVTIj48YSBocmVmPSJodHRwczovL3d3dy5pZXRmLm9y
Zy9tYWlsbWFuL2xpc3RpbmZvL2RvdHMiPmh0dHBzOi8vd3d3LmlldGYub3JnL21haWxtYW4vbGlz
dGluZm8vZG90czwvYT48bzpwPjwvbzpwPjwvc3Bhbj48L3ByZT4NCjwvYmxvY2txdW90ZT4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPiZuYnNwOzwvbzpwPjwv
c3Bhbj48L3A+DQo8L2Rpdj4NCjwvYm9keT4NCjwvaHRtbD4NCg==

--_000_C02846B1344F344EB4FAA6FA7AF481F12AE8F0D7SZXEMA502MBSchi_--


From nobody Mon Oct 26 06:45:05 2015
Return-Path: <amortensen@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98BF51B2E9F for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 06:45:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.699
X-Spam-Level: 
X-Spam-Status: No, score=-1.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NF8paZwKoL99 for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 06:45:01 -0700 (PDT)
Received: from mail-ig0-x22c.google.com (mail-ig0-x22c.google.com [IPv6:2607:f8b0:4001:c05::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6C16B1B2EA0 for <dots@ietf.org>; Mon, 26 Oct 2015 06:45:01 -0700 (PDT)
Received: by igbkq10 with SMTP id kq10so58665733igb.0 for <dots@ietf.org>; Mon, 26 Oct 2015 06:45:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=content-type:mime-version:subject:from:in-reply-to:date:cc :message-id:references:to; bh=NraGIzx6S326zCle3sK2S4xLuGLgn95YacQQmAkm89w=; b=HxPnluLxp9f5H9nUvV7Gh3PwLKLgSnzyv9w5WzPaOTE6EVEXeU+XgRL4dDBV/g2PAL SqfR1WWKjPeERjgpSRd+LefIGK2FiMd7QSVW8qQCDpkkWraCffaTeSXBUp8hpj+B00+j 3bOWpYpu0zCL0VkYCTMvNwT+HyKC3o+RzmT6g=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:message-id:references:to; bh=NraGIzx6S326zCle3sK2S4xLuGLgn95YacQQmAkm89w=; b=l+uYBIEHG9FbTSRdK0zzllYM5LLy+YQ8eddHHS+qxCDpPi+HzBlEi8FIaQL5qzeKPN yeGAj/V4qlMU3O3UxLCqHON1tVdHco4FrpgTFIIMRkNkrtZqAnOG0oN9Qr7STpPrU8Q6 bqa+ONM1xUiPUlvqaoNimQiifqxV7y+Oy+0DoWfPrK+mJ1KcG9spB8QSSZu/Bw9EZyqo 7vkNZKL01jLb30Sqqv6nHyX9xDrwNs9cojr3Y82GiNbAdttDGajfZCvJl+FKMOkWUuD1 z53LKAjKcqn5P8gmZixVEuLABMSE/3pAm1Pn9X5qPijUuAFaftQ2wkIRBYkNWNL1gCD4 ErBQ==
X-Gm-Message-State: ALoCoQkUaR5NsRBZPf7hBtV/0Xt4/5BEmIGeDryTqKquiayQZhujTHVT2648kFee2IZO0ZwcKOcb
X-Received: by 10.50.43.134 with SMTP id w6mr19507343igl.32.1445867100583; Mon, 26 Oct 2015 06:45:00 -0700 (PDT)
Received: from desktop-10-16.aa.arbor.net ([216.130.192.3]) by smtp.gmail.com with ESMTPSA id o3sm2713797ioe.11.2015.10.26.06.44.59 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 26 Oct 2015 06:44:59 -0700 (PDT)
Content-Type: multipart/alternative; boundary="Apple-Mail=_BC98AB81-FC9C-4C3E-9F9F-E5CC603008EF"
Mime-Version: 1.0 (Mac OS X Mail 9.0 \(3094\))
From: Andrew Mortensen <amortensen@arbor.net>
In-Reply-To: <562D3971.8040003@gondrom.org>
Date: Mon, 26 Oct 2015 09:44:59 -0400
Message-Id: <97C80264-FBFA-48F5-B7F1-06CEED06E846@arbor.net>
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <562D3971.8040003@gondrom.org>
To: Tobias Gondrom <tobias.gondrom@gondrom.org>
X-Mailer: Apple Mail (2.3094)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/fuKLt0s5zExKtMPtmP8eiheNiNc>
Cc: rdobbins@arbor.net, rdd@cert.org, frank.xialiang@huawei.com, dots@ietf.org
Subject: Re: [Dots] =?utf-8?b?562U5aSNOiAgTmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZv?= =?utf-8?q?r_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 13:45:03 -0000

--Apple-Mail=_BC98AB81-FC9C-4C3E-9F9F-E5CC603008EF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8


> On Oct 25, 2015, at 4:20 PM, Tobias Gondrom =
<tobias.gondrom@gondrom.org> wrote:
>=20
> Hi Frank,=20
>=20
> thank you for your explanations.=20
> It could be helpful to explain in more detail in the next version of =
the draft, e.g. in the introduction section, a bit more about the =
context of the draft in relation to threat signaling. People       =
attending the BOFs and pre-BOF discussion have the context, but it may =
be less clear for a new reader.=20

For the sake of the archives and the ongoing discussion, can you clarify =
if these comments are as co-chair or as an individual? Thanks!

andrew




>=20
> On 19/10/15 05:33, Xialiang (Frank) wrote:
>> Hi Roland and all,
>> See my clarifications:
>>=20
>> -----=E9=82=AE=E4=BB=B6=E5=8E=9F=E4=BB=B6-----
>> =E5=8F=91=E4=BB=B6=E4=BA=BA: Dots [mailto:dots-bounces@ietf.org =
<mailto:dots-bounces@ietf.org>] =E4=BB=A3=E8=A1=A8 Roland Dobbins
>> =E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4: 2015=E5=B9=B410=E6=9C=8819=E6=97=A5=
 11:19
>> =E6=94=B6=E4=BB=B6=E4=BA=BA: dots
>> =E6=8A=84=E9=80=81: Roman D. Danyliw; Tobias Gondrom
>> =E4=B8=BB=E9=A2=98: Re: [Dots] New Version Notification for =
draft-fu-dots-ipfix-extension-00.txt
>>=20
>>=20
>> On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:
>>=20
>>> May I request for a 5 or 10 minutes time slot for presenting the=20
>>> following draft, as an input for the discussion about attack =
telemetry=20
>>> information?
>>  =46rom the DOTS WG charter:
>>=20
>>    The WG will, where appropriate, reuse or extend existing standard
>>    protocols and mechanisms (for example, IPFIX and its associated
>>    templating and extension mechanisms).
>>=20
>> This language in the DOTS WG charter is not intended to suggest a =
general extension of any existing standards such as IPFIX; rather, it is =
intended to note that should an existing standard may be desirable for =
use within the context of threat signaling, the DOTS WG may request an =
extension of said standard to support the DOTS mission of =
standards-based threat signaling.
>>=20
>> draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is =
wholly unconcerned with threat signaling.
>>=20
>> [Frank]: It's related with what information about threat or attack =
can be used for DOTS threat signaling. Do you mean the attack telemetry =
information is not the goal of DOTS?
>>=20
>>  =46rom the DOTS WG charter:
>>=20
>>    Any modification of or extension to existing protocols must be in =
close coordination with the working
>>    groups responsible for the protocol being modified, and may be =
done in this working group after agreement
>>    with all the relevant WGs and responsible Area Directors.
>>=20
>> The above criteria from the DOTS WG charter have not been fulfilled =
with regards to any proposed extension of IPFIX.
>>=20
>> It is respectfully suggested to the chairs that this draft (as in its =
previous iteration) is more suited for the (currently Concluded) IPFIX =
WG, as it is not directly related to the potential use of IPFIX for =
threat signaling, but is more of a proposed general extension of IPFIX. =20=

>>=20
>> [Frank]: =46rom my perspective, this draft is related to the =
potential use of IPFIX for the attack telemetry.
>>=20
>>=20
>> As such, its authors would more profitably direct their efforts in =
this regard by petitioning for a reopening of the IPFIX WG.
>>=20
>> -----------------------------------
>> Roland Dobbins <rdobbins@arbor.net> <mailto:rdobbins@arbor.net>
>>=20
>> _______________________________________________
>> Dots mailing list
>> Dots@ietf.org <mailto:Dots@ietf.org>
>> https://www.ietf.org/mailman/listinfo/dots =
<https://www.ietf.org/mailman/listinfo/dots>
>> _______________________________________________
>> Dots mailing list
>> Dots@ietf.org <mailto:Dots@ietf.org>
>> https://www.ietf.org/mailman/listinfo/dots =
<https://www.ietf.org/mailman/listinfo/dots>
>=20
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--Apple-Mail=_BC98AB81-FC9C-4C3E-9F9F-E5CC603008EF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><br class=3D""><div><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Oct 25, 2015, at 4:20 PM, Tobias Gondrom &lt;<a =
href=3D"mailto:tobias.gondrom@gondrom.org" =
class=3D"">tobias.gondrom@gondrom.org</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D"">
 =20
    <meta content=3D"text/html; charset=3DUTF-8" =
http-equiv=3D"Content-Type" class=3D"">
 =20
  <div bgcolor=3D"#FFFFFF" text=3D"#000000" class=3D"">
    <font face=3D"Arial" class=3D"">Hi Frank, <br class=3D"">
      <br class=3D"">
      thank you for your explanations. <br class=3D"">
      It could be helpful to explain in more detail in the next version
      of the draft, e.g. in the introduction section, a bit more about
      the context of the draft in relation to threat signaling. People
      attending the BOFs and pre-BOF discussion have the context, but it
      may be less clear for a new reader. <br =
class=3D""></font></div></div></blockquote><div><br =
class=3D""></div><div>For the sake of the archives and the ongoing =
discussion, can you clarify if these comments are as co-chair or as an =
individual? Thanks!</div><div><br =
class=3D""></div><div>andrew</div><div><br class=3D""></div><div><br =
class=3D""></div><div><br class=3D""></div><div><br =
class=3D""></div><blockquote type=3D"cite" class=3D""><div class=3D""><div=
 bgcolor=3D"#FFFFFF" text=3D"#000000" class=3D"">
    <br class=3D"">
    <div class=3D"moz-cite-prefix">On 19/10/15 05:33, Xialiang (Frank)
      wrote:<br class=3D"">
    </div>
    <blockquote =
cite=3D"mid:C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.h=
uawei.com" type=3D"cite" class=3D"">
      <pre wrap=3D"" class=3D"">Hi Roland and all,
See my clarifications:

-----=E9=82=AE=E4=BB=B6=E5=8E=9F=E4=BB=B6-----
=E5=8F=91=E4=BB=B6=E4=BA=BA: Dots [<a class=3D"moz-txt-link-freetext" =
href=3D"mailto:dots-bounces@ietf.org">mailto:dots-bounces@ietf.org</a>] =
=E4=BB=A3=E8=A1=A8 Roland Dobbins
=E5=8F=91=E9=80=81=E6=97=B6=E9=97=B4: 2015=E5=B9=B410=E6=9C=8819=E6=97=A5 =
11:19
=E6=94=B6=E4=BB=B6=E4=BA=BA: dots
=E6=8A=84=E9=80=81: Roman D. Danyliw; Tobias Gondrom
=E4=B8=BB=E9=A2=98: Re: [Dots] New Version Notification for =
draft-fu-dots-ipfix-extension-00.txt


On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:

</pre>
      <blockquote type=3D"cite" class=3D"">
        <pre wrap=3D"" class=3D"">May I request for a 5 or 10 minutes =
time slot for presenting the=20
following draft, as an input for the discussion about attack telemetry=20=

information?
</pre>
      </blockquote>
      <pre wrap=3D"" class=3D""> =46rom the DOTS WG charter:

   The WG will, where appropriate, reuse or extend existing standard
   protocols and mechanisms (for example, IPFIX and its associated
   templating and extension mechanisms).

This language in the DOTS WG charter is not intended to suggest a =
general extension of any existing standards such as IPFIX; rather, it is =
intended to note that should an existing standard may be desirable for =
use within the context of threat signaling, the DOTS WG may request an =
extension of said standard to support the DOTS mission of =
standards-based threat signaling.

draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is =
wholly unconcerned with threat signaling.

[Frank]: It's related with what information about threat or attack can =
be used for DOTS threat signaling. Do you mean the attack telemetry =
information is not the goal of DOTS?

 =46rom the DOTS WG charter:

   Any modification of or extension to existing protocols must be in =
close coordination with the working
   groups responsible for the protocol being modified, and may be done =
in this working group after agreement
   with all the relevant WGs and responsible Area Directors.

The above criteria from the DOTS WG charter have not been fulfilled with =
regards to any proposed extension of IPFIX.

It is respectfully suggested to the chairs that this draft (as in its =
previous iteration) is more suited for the (currently Concluded) IPFIX =
WG, as it is not directly related to the potential use of IPFIX for =
threat signaling, but is more of a proposed general extension of IPFIX. =20=


[Frank]: =46rom my perspective, this draft is related to the potential =
use of IPFIX for the attack telemetry.


As such, its authors would more profitably direct their efforts in this =
regard by petitioning for a reopening of the IPFIX WG.

-----------------------------------
Roland Dobbins <a class=3D"moz-txt-link-rfc2396E" =
href=3D"mailto:rdobbins@arbor.net">&lt;rdobbins@arbor.net&gt;</a>

_______________________________________________
Dots mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/m=
ailman/listinfo/dots</a>
_______________________________________________
Dots mailing list
<a class=3D"moz-txt-link-abbreviated" =
href=3D"mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class=3D"moz-txt-link-freetext" =
href=3D"https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/m=
ailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br class=3D"">
  </div>

_______________________________________________<br class=3D"">Dots =
mailing list<br class=3D""><a href=3D"mailto:Dots@ietf.org" =
class=3D"">Dots@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/dots<br =
class=3D""></div></blockquote></div><br class=3D""></body></html>=

--Apple-Mail=_BC98AB81-FC9C-4C3E-9F9F-E5CC603008EF--


From nobody Mon Oct 26 08:09:28 2015
Return-Path: <Stefan.Fouant@corero.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5653D1B3017 for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 08:09:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level: 
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bq1WzoddaF5w for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 08:09:23 -0700 (PDT)
Received: from mail1.bemta8.messagelabs.com (mail1.bemta8.messagelabs.com [216.82.243.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E8EEF1B4895 for <dots@ietf.org>; Mon, 26 Oct 2015 08:08:05 -0700 (PDT)
Received: from [216.82.242.33] by server-6.bemta-8.messagelabs.com id 43/85-31411-5D14E265; Mon, 26 Oct 2015 15:08:05 +0000
X-Env-Sender: Stefan.Fouant@corero.com
X-Msg-Ref: server-11.tower-55.messagelabs.com!1445872084!1377942!1
X-Originating-IP: [71.184.227.49]
X-StarScan-Received: 
X-StarScan-Version: 7.19.2; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 143606 invoked from network); 26 Oct 2015 15:08:04 -0000
Received: from mercury.corero.com (HELO MERCURY.corero.com) (71.184.227.49) by server-11.tower-55.messagelabs.com with AES128-SHA encrypted SMTP; 26 Oct 2015 15:08:04 -0000
Received: from MERCURY.corero.com ([fe80::2c05:6b26:abe2:ad24]) by MERCURY.corero.com ([fe80::2c05:6b26:abe2:ad24%19]) with mapi id 14.03.0248.002; Mon, 26 Oct 2015 11:08:04 -0400
From: Stefan Fouant <Stefan.Fouant@corero.com>
To: Harley Green <harley@br-envision.com>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] DDoS-Alert BGP Extensions
Thread-Index: AdEMyM0jwHLG+X71QFy4Suo1K751BgDN058A
Date: Mon, 26 Oct 2015 15:08:04 +0000
Message-ID: <D253AE4C.383AB%stefan.fouant@corero.com>
References: <005b01d10cc8$cdbc0960$69341c20$@br-envision.com>
In-Reply-To: <005b01d10cc8$cdbc0960$69341c20$@br-envision.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [70.106.201.72]
Content-Type: multipart/alternative; boundary="_000_D253AE4C383ABstefanfouantcorerocom_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/0quqCmjkR2UcByprSWJeEV5-jSY>
Subject: Re: [Dots] DDoS-Alert BGP Extensions
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 15:09:26 -0000

--_000_D253AE4C383ABstefanfouantcorerocom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable


From: Dots <dots-bounces@ietf.org<mailto:dots-bounces@ietf.org>> on behalf =
of Harley Green <harley@br-envision.com<mailto:harley@br-envision.com>>
Organization: BRE
Date: Thursday, October 22, 2015 at 8:54 AM
To: "dots@ietf.org<mailto:dots@ietf.org>" <dots@ietf.org<mailto:dots@ietf.o=
rg>>
Subject: [Dots] DDoS-Alert BGP Extensions

Greetings,
I=92d like to quickly bring your attention to a new draft called DDoS-AE. T=
he purpose is to leverage the capabilities inherent in most BGP speakers to=
 distribute information about detected DDoS attacks so that these devices c=
an respond to those attacks (throttling/filtering traffic). This new approa=
ch overcomes many of the shortcomings of existing standards as it does not =
require new address types, nor does it require all BGP speakers to support =
the capability for it to be effective. The target centric approach also ser=
ves to leverage existing peering relationships/trust/policies to address co=
ncerns of false DDoS Alert announcements. It is primarily an extension to B=
GP, but because its focus is on DDoS mitigation I wanted to share it with t=
his WG as well.

The draft can be found here: http://datatracker.ietf.org/doc/draft-green-id=
r-ddosae/

We have performed analytical studies to demonstrate the potential impact of=
 BGP speakers implementing this capability and the results are very promisi=
ng. I=92d be happy to share the study as well as reference implementation (=
in Quagga) with any interested parties.

Hi Harley,

I finally had a chance to peruse through your draft and here are my initial=
 thoughts. Please note, I am not attempting to start a firestorm or any typ=
e of religious debate, but just lend my observations from many years workin=
g in and around the service provider community supporting DDoS mitigation e=
fforts.

The core premise as outlined in this draft, as indicated in the Introductio=
n is that "BGP enabled devices are also likely to have the ability to filte=
r and/or throttle traffic; they are also widely distributed throughout netw=
orks, making them ideal for mitigating DDoS attacks.=94.  While you are cor=
rect to surmise that many BGP enabled devices (mostly routers) have the abi=
lity to filter and/or throttle traffic, the DDoS problem can not be solved =
with these mechanisms alone=85 surely if that was the case this problem wou=
ld not continue to exist today, or the impact would be much smaller than it=
 is today. Much of the DDoS problem needs to be solved by looking at some s=
emblance of flow state, even if just for a short duration to determine whet=
her flows are legitimate or not. This is not something that routers are ver=
y good at and in fact runs counter to their very purpose. So we are left wi=
th very simple traffic filtering applications (essentially ACL distribution=
) and my belief is that BGP Flowspec already does a pretty good job in that=
 regard=85 on that point it seems that this draft is attempting to supplant=
 some of the very capabilities that are already inherent in Flowspec=85

=85which leads me to my next point=85 Flowspec has been around for a long t=
ime. And in my daily interactions at almost all of the large tier1/2/3 carr=
iers, I have yet to see many operators implement it. It=92s not to say it=
=92s flawed because it=92s a brilliant protocol. But in my experience, core=
 network operators really depend on BGP for their core operations and are v=
ery reluctant to make any changes in protocol operations because of this de=
pendancy. I understand the BGP-AE protocol extensions are by their very nat=
ure optional, but let us look at the penetration of Flowspec to date to get=
 an idea on the likelihood of deployment of such a protocol.

My last thought is that I believe enabling BGP for such means is a fairly h=
eavy price to pay for anything that may want to facilitate the distribution=
 of coordinated DDoS attack mitigation mechamisms. Such might be the case w=
ith a Virtual Machine implemented on a hypervisor which would attempt to si=
gnal upstream to indicate desire of mitigation services. Should such a VM r=
equire implementation of a full BGP stack in order to participate? I would =
hope not. For this reason alone, I still believe DOTS to be the best protoc=
ol for enablement of such coordinated protection mechanisms.

Stefan Fouant
JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNCI, CISSP
Senior Security Engineer
Corero Network Security
Mobile: +1.703.625.6243

--_000_D253AE4C383ABstefanfouantcorerocom_
Content-Type: text/html; charset="Windows-1252"
Content-ID: <7D114CDE91EF3E45BFFA72FEB6EDFA2B@corero.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space;">
<div>
<div style=3D"color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-s=
ize: 14px;">
<br>
</div>
</div>
<span id=3D"OLK_SRC_BODY_SECTION" style=3D"color: rgb(0, 0, 0); font-family=
: Calibri, sans-serif; font-size: 14px;">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Dots &lt;<a href=3D"mailto:do=
ts-bounces@ietf.org">dots-bounces@ietf.org</a>&gt; on behalf of Harley Gree=
n &lt;<a href=3D"mailto:harley@br-envision.com">harley@br-envision.com</a>&=
gt;<br>
<span style=3D"font-weight:bold">Organization: </span>BRE<br>
<span style=3D"font-weight:bold">Date: </span>Thursday, October 22, 2015 at=
 8:54 AM<br>
<span style=3D"font-weight:bold">To: </span>&quot;<a href=3D"mailto:dots@ie=
tf.org">dots@ietf.org</a>&quot; &lt;<a href=3D"mailto:dots@ietf.org">dots@i=
etf.org</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>[Dots] DDoS-Alert BGP Exte=
nsions<br>
</div>
<div><br>
</div>
<blockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"BORDER-LEFT:=
 #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micro=
soft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" x=
mlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:/=
/www.w3.org/TR/REC-html40">
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Greetings,<o:p></o:p></p>
<p class=3D"MsoNormal">I=92d like to quickly bring your attention to a new =
draft called DDoS-AE. The purpose is to leverage the capabilities inherent =
in most BGP speakers to distribute information about detected DDoS attacks =
so that these devices can respond to
 those attacks (throttling/filtering traffic). This new approach overcomes =
many of the shortcomings of existing standards as it does not require new a=
ddress types, nor does it require all BGP speakers to support the capabilit=
y for it to be effective. The target
 centric approach also serves to leverage existing peering relationships/tr=
ust/policies to address concerns of false DDoS Alert announcements. It is p=
rimarily an extension to BGP, but because its focus is on DDoS mitigation I=
 wanted to share it with this WG
 as well.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">The draft can be found here: <a href=3D"http://datat=
racker.ietf.org/doc/draft-green-idr-ddosae/">
http://datatracker.ietf.org/doc/draft-green-idr-ddosae/</a><o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">We have performed analytical studies to demonstrate =
the potential impact of BGP speakers implementing this capability and the r=
esults are very promising. I=92d be happy to share the study as well as ref=
erence implementation (in Quagga) with
 any interested parties.</p>
</div>
</div>
</div>
</blockquote>
</span>
<div><br>
</div>
<div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;">Hi Harley=
,</div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;"><br>
</div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;">I finally=
 had a chance to peruse through your draft and here are my initial thoughts=
. Please note, I am not attempting to start a firestorm or any type of reli=
gious debate, but just lend my observations
 from many years working in and around the service provider community suppo=
rting DDoS mitigation efforts.</div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;"><br>
</div>
<div><font face=3D"Calibri,sans-serif" style=3D"font-family: Calibri, sans-=
serif; font-size: 14px;">The core premise as outlined in this draft, as ind=
icated in the Introduction is that &quot;BGP enabled devices are also likel=
y to have the ability to filter and/or throttle
 traffic; they are also widely distributed throughout networks, making them=
 ideal for mitigating DDoS attacks.=94. &nbsp;While you are correct to surm=
ise that many BGP enabled devices (mostly routers) have the ability to filt=
er and/or throttle traffic, the DDoS problem
 can not be solved with these mechanisms alone</font><font face=3D"Calibri,=
sans-serif">=85 surely if that was the case this problem would not continue=
 to exist today, or the impact would be much smaller than it is today. Much=
 of the DDoS problem needs to be solved
 by looking at some semblance of flow state, even if just for a short durat=
ion to determine whether flows are legitimate or not. This is not something=
 that routers are very good at and in fact runs counter to their very purpo=
se.&nbsp;</font><font face=3D"Calibri,sans-serif">So
 we are left with very simple traffic filtering applications (essentially A=
CL distribution) and my belief is that BGP Flowspec already does a pretty g=
ood job in that regard</font><font face=3D"Calibri,sans-serif">=85 on that =
point it seems that this draft is attempting
 to supplant some of the very capabilities that are already inherent in Flo=
wspec</font><font face=3D"Calibri,sans-serif">=85</font></div>
<div><font face=3D"Calibri,sans-serif"><br>
</font></div>
<div>=85which leads me to my next point=85 Flowspec has been around for a l=
ong time. And in my daily interactions at almost all of the large tier1/2/3=
 carriers, I have yet to see many operators implement it. It=92s not to say=
 it=92s flawed because it=92s a brilliant
 protocol. But in my experience, core network operators really depend on BG=
P for their core operations and are very reluctant to make any changes in p=
rotocol operations because of this dependancy. I understand the BGP-AE prot=
ocol extensions are by their very
 nature optional, but let us look at the penetration of Flowspec to date to=
 get an idea on the likelihood of deployment of such a protocol.&nbsp;</div=
>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;"><font fac=
e=3D"Calibri,sans-serif"><br>
</font></div>
<div><font face=3D"Calibri,sans-serif">My last thought is that&nbsp;I&nbsp;=
believe enabling BGP for such means is a fairly heavy price to pay for anyt=
hing that may want to&nbsp;</font><font face=3D"Calibri,sans-serif">facilit=
ate the distribution of coordinated DDoS attack mitigation
 mechamisms. Such might be the case with a Virtual Machine implemented on a=
 hypervisor which would attempt to signal upstream to indicate desire of mi=
tigation services. Should such a VM require implementation of a full BGP st=
ack in order to participate?&nbsp;I would
 hope not. For this reason alone,&nbsp;I still believe DOTS to be the best =
protocol for enablement of such coordinated protection mechanisms.</font></=
div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;"><br>
</div>
<div style=3D"font-size: 14px; font-family: Calibri, sans-serif;"><span sty=
le=3D"font-family: AndaleMono; font-size: 12px;"><span style=3D"color: rgb(=
64, 64, 64); font-size: 11pt; font-family: Calibri, sans-serif;">Stefan Fou=
ant</span></span>
<div>
<p class=3D"MsoNormal" style=3D"margin-top: 0cm; margin-right: 0cm; margin-=
left: 0cm; font-family: Calibri, sans-serif;">
<span style=3D"color: rgb(64, 64, 64);">JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNC=
I, CISSP</span></p>
<p class=3D"MsoNormal" style=3D"margin-top: 0cm; margin-right: 0cm; margin-=
left: 0cm; font-family: Calibri, sans-serif;">
<span style=3D"color: rgb(64, 64, 64); font-size: 11pt;">Senior Security En=
gineer</span></p>
<p class=3D"MsoNormal" style=3D"margin-top: 0cm; margin-right: 0cm; margin-=
left: 0cm; font-family: Calibri, sans-serif;">
<b><span style=3D"color: rgb(54, 95, 145);">Corero Network Security<o:p></o=
:p></span></b></p>
<p class=3D"MsoNormal" style=3D"margin-top: 0cm; margin-right: 0cm; margin-=
left: 0cm; font-family: Calibri, sans-serif;">
<span style=3D"color: rgb(64, 64, 64);">Mobile: &#43;1.703.625.6243</span><=
/p>
</div>
</div>
</div>
</body>
</html>

--_000_D253AE4C383ABstefanfouantcorerocom_--


From nobody Mon Oct 26 13:28:40 2015
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54F331A01FA for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 13:28:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -96.364
X-Spam-Level: 
X-Spam-Status: No, score=-96.364 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=1.951, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0UL8WTgxMblW for <dots@ietfa.amsl.com>; Mon, 26 Oct 2015 13:28:36 -0700 (PDT)
Received: from lvps5-35-241-16.dedicated.hosteurope.de (www.gondrom.org [5.35.241.16]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C5F531A01FC for <dots@ietf.org>; Mon, 26 Oct 2015 13:28:35 -0700 (PDT)
Received: from [192.168.178.26] (x590f87fe.dyn.telefonica.de [89.15.135.254]) by lvps5-35-241-16.dedicated.hosteurope.de (Postfix) with ESMTPSA id 1948762B15; Mon, 26 Oct 2015 21:28:33 +0100 (CET)
DomainKey-Signature: a=rsa-sha1;  q=dns; c=nofws; s=default; d=gondrom.org; b=ZNb7nQr8J+zpXz35RLJyYP4dfyPmD0K5cGNp4AUQCKDw1p/XK6U3RBwFhq3wBXrBdLrBUvKXAs+VVcJ0ZkMsn4g32fzBvoPpUPIq5djFW/kWotXlmkO2ta+Amu923K3NuftYgaURpSVtWq6MCQloFMQV6vMQ1U1xCTIo8dgSfuU=; h=Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type;
Message-ID: <562E8CF0.8000207@gondrom.org>
Date: Mon, 26 Oct 2015 21:28:32 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: amortensen@arbor.net
References: <C02846B1344F344EB4FAA6FA7AF481F12AE8DDF2@SZXEMA502-MBS.china.huawei.com> <9DDE9CA9-1147-4CE0-8494-E4683B77333F@arbor.net> <C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com> <562D3971.8040003@gondrom.org> <97C80264-FBFA-48F5-B7F1-06CEED06E846@arbor.net>
In-Reply-To: <97C80264-FBFA-48F5-B7F1-06CEED06E846@arbor.net>
Content-Type: multipart/alternative; boundary="------------050102050901020300020606"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/z-Ji0-QHnhH7tLiETPP7CnTAnk4>
Cc: rdobbins@arbor.net, rdd@cert.org, frank.xialiang@huawei.com, dots@ietf.org
Subject: Re: [Dots] =?utf-8?b?562U5aSNOiAgTmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZv?= =?utf-8?q?r_draft-fu-dots-ipfix-extension-00=2Etxt?=
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 20:28:39 -0000

This is a multi-part message in MIME format.
--------------050102050901020300020606
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hi Andrew,

thank you for reminding me.
I forgot to explicitly take off my chair hat before replying to Frank. 
Apologies. I shall be more thorough with that.

For the archives, I meant:
<WG chair hat = off>
Hi Frank,

thank you for your explanations.
It could be helpful to explain in more detail in the next version of the 
draft, e.g. in the introduction section, a bit more about the context of 
the draft in relation to threat signaling. People attending the BOFs and 
pre-BOF discussion have the context, but it may be less clear for a new 
reader.

Best regards, Tobias
</WG chair hat = off>

Best, Tobias


On 26/10/15 14:44, Andrew Mortensen wrote:
>
>> On Oct 25, 2015, at 4:20 PM, Tobias Gondrom 
>> <tobias.gondrom@gondrom.org <mailto:tobias.gondrom@gondrom.org>> wrote:
>>
>> Hi Frank,
>>
>> thank you for your explanations.
>> It could be helpful to explain in more detail in the next version of 
>> the draft, e.g. in the introduction section, a bit more about the 
>> context of the draft in relation to threat signaling. People 
>> attending the BOFs and pre-BOF discussion have the context, but it 
>> may be less clear for a new reader.
>
> For the sake of the archives and the ongoing discussion, can you 
> clarify if these comments are as co-chair or as an individual? Thanks!
>
> andrew
>
>
>
>
>>
>> On 19/10/15 05:33, Xialiang (Frank) wrote:
>>> Hi Roland and all,
>>> See my clarifications:
>>>
>>> -----邮件原件-----
>>> 发件人: Dots [mailto:dots-bounces@ietf.org] 代表 Roland Dobbins
>>> 发送时间: 2015年10月19日 11:19
>>> 收件人: dots
>>> 抄送: Roman D. Danyliw; Tobias Gondrom
>>> 主题: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt
>>>
>>>
>>> On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:
>>>
>>>> May I request for a 5 or 10 minutes time slot for presenting the
>>>> following draft, as an input for the discussion about attack telemetry
>>>> information?
>>>   From the DOTS WG charter:
>>>
>>>     The WG will, where appropriate, reuse or extend existing standard
>>>     protocols and mechanisms (for example, IPFIX and its associated
>>>     templating and extension mechanisms).
>>>
>>> This language in the DOTS WG charter is not intended to suggest a general extension of any existing standards such as IPFIX; rather, it is intended to note that should an existing standard may be desirable for use within the context of threat signaling, the DOTS WG may request an extension of said standard to support the DOTS mission of standards-based threat signaling.
>>>
>>> draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is wholly unconcerned with threat signaling.
>>>
>>> [Frank]: It's related with what information about threat or attack can be used for DOTS threat signaling. Do you mean the attack telemetry information is not the goal of DOTS?
>>>
>>>   From the DOTS WG charter:
>>>
>>>     Any modification of or extension to existing protocols must be in close coordination with the working
>>>     groups responsible for the protocol being modified, and may be done in this working group after agreement
>>>     with all the relevant WGs and responsible Area Directors.
>>>
>>> The above criteria from the DOTS WG charter have not been fulfilled with regards to any proposed extension of IPFIX.
>>>
>>> It is respectfully suggested to the chairs that this draft (as in its previous iteration) is more suited for the (currently Concluded) IPFIX WG, as it is not directly related to the potential use of IPFIX for threat signaling, but is more of a proposed general extension of IPFIX.
>>>
>>> [Frank]: From my perspective, this draft is related to the potential use of IPFIX for the attack telemetry.
>>>
>>>
>>> As such, its authors would more profitably direct their efforts in this regard by petitioning for a reopening of the IPFIX WG.
>>>
>>> -----------------------------------
>>> Roland Dobbins<rdobbins@arbor.net>
>>>
>>> _______________________________________________
>>> Dots mailing list
>>> Dots@ietf.org
>>> https://www.ietf.org/mailman/listinfo/dots
>>> _______________________________________________
>>> Dots mailing list
>>> Dots@ietf.org
>>> https://www.ietf.org/mailman/listinfo/dots
>>
>> _______________________________________________
>> Dots mailing list
>> Dots@ietf.org <mailto:Dots@ietf.org>
>> https://www.ietf.org/mailman/listinfo/dots
>
>
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


--------------050102050901020300020606
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Arial">Hi Andrew, <br>
      <br>
      thank you for reminding me. <br>
      I forgot to explicitly take off my chair hat before replying to
      Frank. Apologies. I shall be more thorough with that. <br>
      <br>
      For the archives, I meant: <br>
      &lt;WG chair hat = off&gt;<br>
    </font><font face="Arial"><font face="Arial">Hi Frank, <br>
        <br>
        thank you for your explanations. <br>
        It could be helpful to explain in more detail in the next
        version of the draft, e.g. in the introduction section, a bit
        more about the context of the draft in relation to threat
        signaling. People attending the BOFs and pre-BOF discussion have
        the context, but it may be less clear for a new reader. <br>
        <br>
        Best regards, Tobias<br>
      </font></font><font face="Arial"><font face="Arial"><font
          face="Arial">&lt;/WG </font></font></font><font face="Arial"><font
        face="Arial"><font face="Arial"><font face="Arial">chair </font>hat
          = off&gt;<br>
        </font><br>
        Best, Tobias<br>
        <br>
      </font></font><br>
    <div class="moz-cite-prefix">On 26/10/15 14:44, Andrew Mortensen
      wrote:<br>
    </div>
    <blockquote
      cite="mid:97C80264-FBFA-48F5-B7F1-06CEED06E846@arbor.net"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <br class="">
      <div>
        <blockquote type="cite" class="">
          <div class="">On Oct 25, 2015, at 4:20 PM, Tobias Gondrom &lt;<a
              moz-do-not-send="true"
              href="mailto:tobias.gondrom@gondrom.org" class="">tobias.gondrom@gondrom.org</a>&gt;
            wrote:</div>
          <br class="Apple-interchange-newline">
          <div class="">
            <meta content="text/html; charset=UTF-8"
              http-equiv="Content-Type" class="">
            <div bgcolor="#FFFFFF" text="#000000" class=""> <font
                class="" face="Arial">Hi Frank, <br class="">
                <br class="">
                thank you for your explanations. <br class="">
                It could be helpful to explain in more detail in the
                next version of the draft, e.g. in the introduction
                section, a bit more about the context of the draft in
                relation to threat signaling. People attending the BOFs
                and pre-BOF discussion have the context, but it may be
                less clear for a new reader. <br class="">
              </font></div>
          </div>
        </blockquote>
        <div><br class="">
        </div>
        <div>For the sake of the archives and the ongoing discussion,
          can you clarify if these comments are as co-chair or as an
          individual? Thanks!</div>
        <div><br class="">
        </div>
        <div>andrew</div>
        <div><br class="">
        </div>
        <div><br class="">
        </div>
        <div><br class="">
        </div>
        <div><br class="">
        </div>
        <blockquote type="cite" class="">
          <div class="">
            <div bgcolor="#FFFFFF" text="#000000" class=""> <br
                class="">
              <div class="moz-cite-prefix">On 19/10/15 05:33, Xialiang
                (Frank) wrote:<br class="">
              </div>
              <blockquote
cite="mid:C02846B1344F344EB4FAA6FA7AF481F12AE8DE38@SZXEMA502-MBS.china.huawei.com"
                type="cite" class="">
                <pre class="" wrap="">Hi Roland and all,
See my clarifications:

-----邮件原件-----
发件人: Dots [<a moz-do-not-send="true" class="moz-txt-link-freetext" href="mailto:dots-bounces@ietf.org">mailto:dots-bounces@ietf.org</a>] 代表 Roland Dobbins
发送时间: 2015年10月19日 11:19
收件人: dots
抄送: Roman D. Danyliw; Tobias Gondrom
主题: Re: [Dots] New Version Notification for draft-fu-dots-ipfix-extension-00.txt


On 19 Oct 2015, at 9:14, Xialiang (Frank) wrote:

</pre>
                <blockquote type="cite" class="">
                  <pre class="" wrap="">May I request for a 5 or 10 minutes time slot for presenting the 
following draft, as an input for the discussion about attack telemetry 
information?
</pre>
                </blockquote>
                <pre class="" wrap=""> From the DOTS WG charter:

   The WG will, where appropriate, reuse or extend existing standard
   protocols and mechanisms (for example, IPFIX and its associated
   templating and extension mechanisms).

This language in the DOTS WG charter is not intended to suggest a general extension of any existing standards such as IPFIX; rather, it is intended to note that should an existing standard may be desirable for use within the context of threat signaling, the DOTS WG may request an extension of said standard to support the DOTS mission of standards-based threat signaling.

draft-fu-dots-ipfix-extension-00 does not meet these criteria; it is wholly unconcerned with threat signaling.

[Frank]: It's related with what information about threat or attack can be used for DOTS threat signaling. Do you mean the attack telemetry information is not the goal of DOTS?

 From the DOTS WG charter:

   Any modification of or extension to existing protocols must be in close coordination with the working
   groups responsible for the protocol being modified, and may be done in this working group after agreement
   with all the relevant WGs and responsible Area Directors.

The above criteria from the DOTS WG charter have not been fulfilled with regards to any proposed extension of IPFIX.

It is respectfully suggested to the chairs that this draft (as in its previous iteration) is more suited for the (currently Concluded) IPFIX WG, as it is not directly related to the potential use of IPFIX for threat signaling, but is more of a proposed general extension of IPFIX.  

[Frank]: From my perspective, this draft is related to the potential use of IPFIX for the attack telemetry.


As such, its authors would more profitably direct their efforts in this regard by petitioning for a reopening of the IPFIX WG.

-----------------------------------
Roland Dobbins <a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="mailto:rdobbins@arbor.net">&lt;rdobbins@arbor.net&gt;</a>

_______________________________________________
Dots mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
_______________________________________________
Dots mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
              </blockquote>
              <br class="">
            </div>
            _______________________________________________<br class="">
            Dots mailing list<br class="">
            <a moz-do-not-send="true" href="mailto:Dots@ietf.org"
              class="">Dots@ietf.org</a><br class="">
            <a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a><br class="">
          </div>
        </blockquote>
      </div>
      <br class="">
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Dots mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Dots@ietf.org">Dots@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/dots">https://www.ietf.org/mailman/listinfo/dots</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------050102050901020300020606--


From nobody Thu Oct 29 05:22:05 2015
Return-Path: <harley@br-envision.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE3271B2E45 for <dots@ietfa.amsl.com>; Thu, 29 Oct 2015 05:22:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 4.667
X-Spam-Level: ****
X-Spam-Status: No, score=4.667 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DYN_RDNS_AND_INLINE_IMAGE=1.168, FH_HOST_EQ_D_D_D_D=0.765, FH_HOST_EQ_D_D_D_DB=0.888, HELO_MISMATCH_COM=0.553, HOST_MISMATCH_NET=0.311, HTML_MESSAGE=0.001, RDNS_DYNAMIC=0.982] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LhB3ekxYqVDB for <dots@ietfa.amsl.com>; Thu, 29 Oct 2015 05:21:57 -0700 (PDT)
Received: from mail.br-envision.com (70-90-80-254-washington-dc.hfc.comcastbusiness.net [70.90.80.254]) by ietfa.amsl.com (Postfix) with ESMTP id C57781B2E46 for <dots@ietf.org>; Thu, 29 Oct 2015 05:21:56 -0700 (PDT)
Received: from harleyPC (unknown [172.16.1.30]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.br-envision.com (Postfix) with ESMTP id 6FE3415D566; Thu, 29 Oct 2015 07:21:10 -0500 (EST)
From: "Harley Green" <harley@br-envision.com>
To: "'Stefan Fouant'" <Stefan.Fouant@corero.com>, <dots@ietf.org>
References: <005b01d10cc8$cdbc0960$69341c20$@br-envision.com> <D253AE4C.383AB%stefan.fouant@corero.com>
In-Reply-To: <D253AE4C.383AB%stefan.fouant@corero.com>
Date: Thu, 29 Oct 2015 08:21:52 -0400
Organization: BRE
Message-ID: <00ee01d11244$65295a20$2f7c0e60$@br-envision.com>
MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_000_00EF_01D11222.DE17BA20"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQHb3jCE1cHp1bK6oTnRjwJVJATgDwH8t3SDnlzfKNA=
Content-Language: en-us
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/OIn_N7JP_Je73Y4CX8kxzh2JVbk>
Subject: Re: [Dots] DDoS-Alert BGP Extensions
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Oct 2015 12:22:02 -0000

This is a multipart message in MIME format.

------=_NextPart_000_00EF_01D11222.DE17BA20
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_00F0_01D11222.DE17BA20"


------=_NextPart_001_00F0_01D11222.DE17BA20
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi Stefan,

Thank you for the thoughtful feedback. Your points are well received. I
think that if anything, the points you raise help make the case for why
something like what is in DDoS-AE is needed. 

 

Just because not all DDoS attacks can be mitigated by any single device or
technology, as of yet, does not necessarily mean that we should not pursue
legitimate options that have the potential to mitigate a large subset of
DDoS and other network attacks. One of the advantages of this BGP based DDoS
Alert system is that devices that are well suited to performing the flow
state monitoring you mention can be used in parallel to existing routers
that specialize in moving packets quickly and performing more simplistic ACL
enforcement. Many tools already exist that could be placed on these more
specialized DDoS detection devices, if not already present, that would allow
them to send their detections as DDoS Alerts through BGP, such as an iBGP
speaker, without being full BGP participants on a core network. 

 

Once the Alert has been sent into BGP, its propagated like an update to the
prefix that is under attack. This is a unique advantage over flowspec and
other signaling protocols in that many different systems are already setup
to monitor BGP updates, not just routers. This allows routers as well as
other network appliances to see the Alert and implement appropriate filters
to throttle/drop the attack traffic. The DDoS-AE based Alerts would have
wider visibility than flowspec based alerts because they would be
distributed everywhere the update for the prefix would normally go, rather
than stopping at the first BGP speaker that has not negotiated support for
flowspec capabilities. This gives the DDoS-AE based alerts the chance to
reach the widest audience, even reaching BGP monitors that could help
propagate the Alert into other DDoS signaling systems (proprietary or
otherwise). Unlike new signaling protocols it does not require a lot of new
infrastructure in the form of VMs or devices or communications protocols in
order to begin seeing immediate results. Modification of existing BGP
speakers to enable the DDoS-AE BGP extension would be relatively minor,
something that could be included in a regularly scheduled patch.

 

You are absolutely correct that the large network providers are going to
resist any sort of technology change for security's sake, as they are not in
the business of DDoS mitigation, so much as making sure all traffic gets to
where it is supposed to go as quickly as possible. While these providers
would be the ideal location for implementing the DDoS mitigation mechanisms
(filters/TE), if enough smaller providers and organizations implement the
(filters/TE) then these core providers are still useful in that they support
the DDoS-AE Alert distribution. Even if these core providers know nothing
about DDoS-AE, simply passing the BGP Update message with the DDoS-AE
(optional/transitive) attribute, which they would do as BGP speakers, makes
them facilitators of the mass distribution of these alerts.

 

I would think that having redundant communication paths for signaling
information about network attacks and coordinating the responses would be
highly desirable. Leveraging existing proprietary systems for vendor
specific devices, DOTS, flowspec, and DDoS-AE would greatly increase the
resiliency of networks to attacks and ensure coordination continues even if
individual systems or protocols fail.

 

 

Harley Green

 

bre

 

 

 

From: Stefan Fouant [mailto:Stefan.Fouant@corero.com] 
Sent: Monday, October 26, 2015 11:08 AM
To: Harley Green; dots@ietf.org
Subject: Re: [Dots] DDoS-Alert BGP Extensions

 

 

From: Dots <dots-bounces@ietf.org> on behalf of Harley Green
<harley@br-envision.com>
Organization: BRE
Date: Thursday, October 22, 2015 at 8:54 AM
To: "dots@ietf.org" <dots@ietf.org>
Subject: [Dots] DDoS-Alert BGP Extensions

 

Greetings,

I'd like to quickly bring your attention to a new draft called DDoS-AE. The
purpose is to leverage the capabilities inherent in most BGP speakers to
distribute information about detected DDoS attacks so that these devices can
respond to those attacks (throttling/filtering traffic). This new approach
overcomes many of the shortcomings of existing standards as it does not
require new address types, nor does it require all BGP speakers to support
the capability for it to be effective. The target centric approach also
serves to leverage existing peering relationships/trust/policies to address
concerns of false DDoS Alert announcements. It is primarily an extension to
BGP, but because its focus is on DDoS mitigation I wanted to share it with
this WG as well.

 

The draft can be found here:
http://datatracker.ietf.org/doc/draft-green-idr-ddosae/

 

We have performed analytical studies to demonstrate the potential impact of
BGP speakers implementing this capability and the results are very
promising. I'd be happy to share the study as well as reference
implementation (in Quagga) with any interested parties.

 

Hi Harley,

 

I finally had a chance to peruse through your draft and here are my initial
thoughts. Please note, I am not attempting to start a firestorm or any type
of religious debate, but just lend my observations from many years working
in and around the service provider community supporting DDoS mitigation
efforts.

 

The core premise as outlined in this draft, as indicated in the Introduction
is that "BGP enabled devices are also likely to have the ability to filter
and/or throttle traffic; they are also widely distributed throughout
networks, making them ideal for mitigating DDoS attacks.".  While you are
correct to surmise that many BGP enabled devices (mostly routers) have the
ability to filter and/or throttle traffic, the DDoS problem can not be
solved with these mechanisms alone. surely if that was the case this problem
would not continue to exist today, or the impact would be much smaller than
it is today. Much of the DDoS problem needs to be solved by looking at some
semblance of flow state, even if just for a short duration to determine
whether flows are legitimate or not. This is not something that routers are
very good at and in fact runs counter to their very purpose. So we are left
with very simple traffic filtering applications (essentially ACL
distribution) and my belief is that BGP Flowspec already does a pretty good
job in that regard. on that point it seems that this draft is attempting to
supplant some of the very capabilities that are already inherent in
Flowspec.

 

.which leads me to my next point. Flowspec has been around for a long time.
And in my daily interactions at almost all of the large tier1/2/3 carriers,
I have yet to see many operators implement it. It's not to say it's flawed
because it's a brilliant protocol. But in my experience, core network
operators really depend on BGP for their core operations and are very
reluctant to make any changes in protocol operations because of this
dependancy. I understand the BGP-AE protocol extensions are by their very
nature optional, but let us look at the penetration of Flowspec to date to
get an idea on the likelihood of deployment of such a protocol. 

 

My last thought is that I believe enabling BGP for such means is a fairly
heavy price to pay for anything that may want to facilitate the distribution
of coordinated DDoS attack mitigation mechamisms. Such might be the case
with a Virtual Machine implemented on a hypervisor which would attempt to
signal upstream to indicate desire of mitigation services. Should such a VM
require implementation of a full BGP stack in order to participate? I would
hope not. For this reason alone, I still believe DOTS to be the best
protocol for enablement of such coordinated protection mechanisms.

 

Stefan Fouant 

JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNCI, CISSP

Senior Security Engineer

Corero Network Security

Mobile: +1.703.625.6243


------=_NextPart_001_00F0_01D11222.DE17BA20
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 =
(filtered medium)"><!--[if !mso]><style>v\:* =
{behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle19
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Hi Stefan,<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Thank you for the =
thoughtful feedback. Your points are well received. I think that if =
anything, the points you raise help make the case for why something like =
what is in DDoS-AE is needed. <o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Just because not all =
DDoS attacks can be mitigated by any single device or technology, as of =
yet, does not necessarily mean that we should not pursue legitimate =
options that have the potential to mitigate a large subset of DDoS and =
other network attacks. One of the advantages of this BGP based DDoS =
Alert system is that devices that are well suited to performing the flow =
state monitoring you mention can be used in parallel to existing routers =
that specialize in moving packets quickly and performing more simplistic =
ACL enforcement. Many tools already exist that could be placed on these =
more specialized DDoS detection devices, if not already present, that =
would allow them to send their detections as DDoS Alerts through BGP, =
such as an iBGP speaker, without being full BGP participants on a core =
network. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Once the Alert has been =
sent into BGP, its propagated like an update to the prefix that is under =
attack. This is a unique advantage over flowspec and other signaling =
protocols in that many different systems are already setup to monitor =
BGP updates, not just routers. This allows routers as well as other =
network appliances to see the Alert and implement appropriate filters to =
throttle/drop the attack traffic. The DDoS-AE based Alerts would have =
wider visibility than flowspec based alerts because they would be =
distributed everywhere the update for the prefix would normally go, =
rather than stopping at the first BGP speaker that has not negotiated =
support for flowspec capabilities. This gives the DDoS-AE based alerts =
the chance to reach the widest audience, even reaching BGP monitors that =
could help propagate the Alert into other DDoS signaling systems =
(proprietary or otherwise). Unlike new signaling protocols it does not =
require a lot of new infrastructure in the form of VMs or devices or =
communications protocols in order to begin seeing immediate results. =
Modification of existing BGP speakers to enable the DDoS-AE BGP =
extension would be relatively minor, something that could be included in =
a regularly scheduled patch.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>You are absolutely =
correct that the large network providers are going to resist any sort of =
technology change for security&#8217;s sake, as they are not in the =
business of DDoS mitigation, so much as making sure all traffic gets to =
where it is supposed to go as quickly as possible. While these providers =
would be the ideal location for implementing the DDoS mitigation =
mechanisms (filters/TE), if enough smaller providers and organizations =
implement the (filters/TE) then these core providers are still useful in =
that they support the DDoS-AE Alert distribution. Even if these core =
providers know nothing about DDoS-AE, simply passing the BGP Update =
message with the DDoS-AE (optional/transitive) attribute, which they =
would do as BGP speakers, makes them facilitators of the mass =
distribution of these alerts.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>I would think that =
having redundant communication paths for signaling information about =
network attacks and coordinating the responses would be highly =
desirable. Leveraging existing proprietary systems for vendor specific =
devices, DOTS, flowspec, and DDoS-AE would greatly increase the =
resiliency of networks to attacks and ensure coordination continues even =
if individual systems or protocols fail.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><b><span =
style=3D'font-size:12.0pt;color:#1F497D'>Harley =
Green<o:p></o:p></span></b></p><p class=3DMsoNormal><b><span =
style=3D'font-size:12.0pt;color:#1F497D'><o:p>&nbsp;</o:p></span></b></p>=
<p class=3DMsoNormal><span style=3D'color:#1F497D'><img width=3D135 =
height=3D44 id=3D"Picture_x0020_1" =
src=3D"cid:image001.png@01D11222.B3CDC4D0" =
alt=3Dbre><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
Stefan Fouant [mailto:Stefan.Fouant@corero.com] <br><b>Sent:</b> Monday, =
October 26, 2015 11:08 AM<br><b>To:</b> Harley Green; =
dots@ietf.org<br><b>Subject:</b> Re: [Dots] DDoS-Alert BGP =
Extensions<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div>=
</div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span =
style=3D'color:black'>From: </span></b><span style=3D'color:black'>Dots =
&lt;<a =
href=3D"mailto:dots-bounces@ietf.org">dots-bounces@ietf.org</a>&gt; on =
behalf of Harley Green &lt;<a =
href=3D"mailto:harley@br-envision.com">harley@br-envision.com</a>&gt;<br>=
<b>Organization: </b>BRE<br><b>Date: </b>Thursday, October 22, 2015 at =
8:54 AM<br><b>To: </b>&quot;<a =
href=3D"mailto:dots@ietf.org">dots@ietf.org</a>&quot; &lt;<a =
href=3D"mailto:dots@ietf.org">dots@ietf.org</a>&gt;<br><b>Subject: =
</b>[Dots] DDoS-Alert BGP Extensions<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:10.5pt;color:black'><o:p>&nbsp;</o:p></span></p></div>=
<blockquote style=3D'border:none;border-left:solid #B5C4DF =
4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in' =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE"><div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>Greetings,<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>I&#8217;d like to quickly =
bring your attention to a new draft called DDoS-AE. The purpose is to =
leverage the capabilities inherent in most BGP speakers to distribute =
information about detected DDoS attacks so that these devices can =
respond to those attacks (throttling/filtering traffic). This new =
approach overcomes many of the shortcomings of existing standards as it =
does not require new address types, nor does it require all BGP speakers =
to support the capability for it to be effective. The target centric =
approach also serves to leverage existing peering =
relationships/trust/policies to address concerns of false DDoS Alert =
announcements. It is primarily an extension to BGP, but because its =
focus is on DDoS mitigation I wanted to share it with this WG as =
well.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>The draft can be found =
here: <a =
href=3D"http://datatracker.ietf.org/doc/draft-green-idr-ddosae/">http://d=
atatracker.ietf.org/doc/draft-green-idr-ddosae/</a><o:p></o:p></span></p>=
<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>We have performed =
analytical studies to demonstrate the potential impact of BGP speakers =
implementing this capability and the results are very promising. =
I&#8217;d be happy to share the study as well as reference =
implementation (in Quagga) with any interested =
parties.<o:p></o:p></span></p></div></div></blockquote><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif"'><o:p>&nbsp;</o:p></span></p></div><div><div><p =
class=3DMsoNormal><span style=3D'font-size:10.5pt'>Hi =
Harley,<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.5pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:10.5pt'>I finally had a =
chance to peruse through your draft and here are my initial thoughts. =
Please note, I am not attempting to start a firestorm or any type of =
religious debate, but just lend my observations from many years working =
in and around the service provider community supporting DDoS mitigation =
efforts.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.5pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:10.5pt'>The core premise as =
outlined in this draft, as indicated in the Introduction is that =
&quot;BGP enabled devices are also likely to have the ability to filter =
and/or throttle traffic; they are also widely distributed throughout =
networks, making them ideal for mitigating DDoS attacks.&#8221;. =
&nbsp;While you are correct to surmise that many BGP enabled devices =
(mostly routers) have the ability to filter and/or throttle traffic, the =
DDoS problem can not be solved with these mechanisms alone</span><span =
style=3D'font-size:12.0pt'>&#8230; surely if that was the case this =
problem would not continue to exist today, or the impact would be much =
smaller than it is today. Much of the DDoS problem needs to be solved by =
looking at some semblance of flow state, even if just for a short =
duration to determine whether flows are legitimate or not. This is not =
something that routers are very good at and in fact runs counter to =
their very purpose.&nbsp;So we are left with very simple traffic =
filtering applications (essentially ACL distribution) and my belief is =
that BGP Flowspec already does a pretty good job in that regard&#8230; =
on that point it seems that this draft is attempting to supplant some of =
the very capabilities that are already inherent in =
Flowspec&#8230;</span><span style=3D'font-size:12.0pt;font-family:"Times =
New Roman","serif"'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif"'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif"'>&#8230;which leads me to my next point&#8230; Flowspec =
has been around for a long time. And in my daily interactions at almost =
all of the large tier1/2/3 carriers, I have yet to see many operators =
implement it. It&#8217;s not to say it&#8217;s flawed because it&#8217;s =
a brilliant protocol. But in my experience, core network operators =
really depend on BGP for their core operations and are very reluctant to =
make any changes in protocol operations because of this dependancy. I =
understand the BGP-AE protocol extensions are by their very nature =
optional, but let us look at the penetration of Flowspec to date to get =
an idea on the likelihood of deployment of such a =
protocol.&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:10.5pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt'>My last thought is =
that&nbsp;I&nbsp;believe enabling BGP for such means is a fairly heavy =
price to pay for anything that may want to&nbsp;facilitate the =
distribution of coordinated DDoS attack mitigation mechamisms. Such =
might be the case with a Virtual Machine implemented on a hypervisor =
which would attempt to signal upstream to indicate desire of mitigation =
services. Should such a VM require implementation of a full BGP stack in =
order to participate?&nbsp;I would hope not. For this reason =
alone,&nbsp;I still believe DOTS to be the best protocol for enablement =
of such coordinated protection mechanisms.</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif"'><o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:10.5pt'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#404040'>Stefan =
Fouant</span><span style=3D'font-size:10.5pt'> =
<o:p></o:p></span></p><div><p class=3DMsoNormal><span =
style=3D'color:#404040'>JNCIE-SEC, JNCIE-SP, JNCIE-ENT, JNCI, =
CISSP</span><o:p></o:p></p><p class=3DMsoNormal><span =
style=3D'color:#404040'>Senior Security Engineer</span><o:p></o:p></p><p =
class=3DMsoNormal><b><span style=3D'color:#365F91'>Corero Network =
Security</span></b><o:p></o:p></p><p class=3DMsoNormal><span =
style=3D'color:#404040'>Mobile: =
+1.703.625.6243</span><o:p></o:p></p></div></div></div></div></body></htm=
l>
------=_NextPart_001_00F0_01D11222.DE17BA20--

------=_NextPart_000_00EF_01D11222.DE17BA20
Content-Type: image/png;
	name="image001.png"
Content-Transfer-Encoding: base64
Content-ID: <image001.png@01D11222.B3CDC4D0>

iVBORw0KGgoAAAANSUhEUgAAAIcAAAAsCAYAAAE4O5uxAAAABGdBTUEAAK/INwWK6QAAABl0RVh0
U29mdHdhcmUAQWRvYmUgSW1hZ2VSZWFkeXHJZTwAABJeSURBVHjaYmBABloJ95n0kh0YSASMWEUj
+v4zrChilGzfDzbweaXjARCNiw+yXQBK/wdjIBDNX/Yf2Uw2y7wCwu7RTlQAGmAANWy9ZMeB91jV
aSU4QLEBTu8I5yz+/3ZKLKPSsrv/70Upg+Vy8wr3A6mDQPwBiP2BeCIQrwfiQigfEYZC2YvAXlBa
cvs/qQELEEDoziXLAEao5gCGaws2gNm+TQYMm+suIEIeEhtI/A9APoo8LFb2gwNLKyEBJCRes1mA
zboA7ioQGx+fCegCRhYebgcgfQHIVwAJfrl5w+HX+w9we0BsMB8SM/9/HZ3AiCyPEjvi1ZsSXrb6
LUCKFRB4ADV8IRCD0pQ9NEYuQOVRoptBdtrZBHICFiCAsMXQeZTUapFnwOxc8Z+BxoAFnjSA4QsV
O4Cs4NeJSSCvM3Ilz/r/bW4aWA1H4vT/DIyMKOoY/v93+P+f4cPPBZmCuOX/T/i5IKsQmzwL2AFa
CfOR0moiqFQBxwdEDiS+gJ2ZaQN/x4GG5xUODT9OngQ53BFL+gblJgawPB4AlXfAXyJ5N/xn4OZx
ZFhVguJi2enn/rMJCAjejVT6gDODwUIVJI8IYeRMeQCHB9BASNd+dCGZqWcVlJbe+a+66iEY0yqN
AAQQI44EGwAtuC4AfWDIMBgAq23xf0aP2gRa28NIlKqgjv8M6yoYoTWVAqzUQi43YWzU8pI4eYhD
kBMWpDL6AOQ/QAmV2CkC3Dw87z9MT2AEZr0GoFA9Svb7D3LYf4Uf8zMZcWVdcG6ByTMwPgDa/AA1
+yLXjAwM+8EpG8JmgGZfh9+Lcw6wla0FC/27dRNSvhyd4IhS8EELfZA8uhy6PKiYBqppwFaOgBQZ
QsttB6QQOg8uw7USPjDx8MIrDWx1JEwcSR45Bzpgkf+PnO1ZYAwmg7T/LNxcgkCF/bCmErjaB+Ya
yaadAoy8vO+xlhm4K+9GKL0fq3o0PgqH2bVK4S83932GDdUYiVh+/rX/DxO1QKEHSSOYAFFYYToS
ErKI0Meda5hdqhL+7mkDV708aXMTuHj55r/qDQXLy8+7+v9hkjYjsEDb73FkwkJorgE7ZvKkfkZg
VQ1ynDwQB0CNC4TKb4SKfwTifGjUH4TKXYDKg6rzjQSzr/zcK+/ZeHkFYPXQ7TD5BXQpwESLV8F8
xSA39wpNi3VkABCAGyvmbRqIwmdf7i6dMCC1TOAwspD8AhwJBEIqU0GIpQkbE8mCEFLAIiOUpGJA
DCj+A1VBlSox4fIHDEMyQYXEgsrQSCxQ5B7P57vGdhzHLagSfZJlJ3p3Z7973/e+d/kILaT8jqiu
ShCCntMw7umUIkwI4pSUfr9f+oKOtMWpINP0Ky0OqplDNTD/509W/LkaAZ4rADZw7H3PdvPZNiHU
IJTWQVTuYWv23sok5km3Xe5uPV2oRsbvDy6+39xautE9yPiA5rZlkxDSYjxDTMnPFVxkwYs2/J2d
Y+DXnDShccfhEBD0ffnWCI7z7VFA1lrTYTrf5jHf5O8su9bugBRopI4Pas5ay85uJQbOcaHgEart
1YORDWWwTP/nLy+m1ENfQ3ZfSuhUgIFdjVLr1OO31reHl0NNsrmZbNizdyz07yZ+57NPnw3QQmnz
TV+739MKkVakLAMAeQPiqd8rSRUwlP1scndMFSy4quAjPt6/eMmgJ04iCEpUnI0tnMFbKpsaqkWK
jc9zTMB5Hd7HSV0/KQrGMiR0GkptFhV1HifE9Cnt7g7Ei3QEVM7VGnDvisxKMVY6Ww7g9fU5NKnB
GVA4d16ithLZObl9Gw+kgj6K3JO2CH4X/r7sXn9Sw5T2CGUI+KH04+Xt1PIK/eg7nTELM+ZAKd74
Z6JlpOLd3L6hfRAbEv/vADrkqm2hdXvi4nMP3hgaZZ7GqKkxNsQzM00IRAezooFJwYFA1EFIBRD0
4FlJyEW4XktoliO76ILMrEqf83B9lL7LUvuobGlKvlLVyoBxFRjHpUA/I3gwzn1u5HRJnSxFv2tD
StW7yVOJVGO1F940n9Ov+p46JDgK0isXZGbvr9qQAY8QQEYHftBZEe5FVIBngNLh6flDsD8CkGs1
IXIUUbj6p7p3EXZnDv7gT5w5SfaSXvDgbXeIgodIJiAxBuP2IiHJIe6sEggEwSUEQoT0mgSUmDAj
IioIu3eRGT3qYVaDJ012cxM32WkRE5LsbOdV9aue6pnu6ZrNybGg2GGnXlfPV6/e+95XpQ24l6uS
W0Iy0haD36rz/y8wwuhd4/s0DFAOIDGnU+pCJ7pFG0nSw3CBER6ZVPrRd0zLTptaZOu7M9pwghEC
UUAi1rcZr5xaalu0TCj1yfKp/DCC4agAEbXymQBICQ+q7S/nYkE1TbPsp3NKtj16qartoPObqGtU
JQ5Q43KR0DhUG7XyAETLBLLWDp/RKTRbG0qSwRMojwab7cn18/tX0NZVqYqFLVBy/6+PXs9vZ35Z
vJvn1DvuHRUOkmLJD/yEV7QWsNaNS4ci1hqKyDz9NDJqjWgF25ub+QdfHPcjATvLPghkUsfF60Hn
N6U6YDEhZvj4Ih8aLx5z23fu7kXQEuk5gDALvQoe4qFoGb7YrVsES+7sjPPaaVFVMx2mFNmq2weR
rIDlvOr8elQkhVVk59CdkBZuH3Zg1wQgPBSJVjHVxuMLtH8uv1MzgJwBXS/HQNq4zbtKg3EOjl+R
bQewF31q0PmF1hFwD5hwfV4bTES8qoRgFSQXXOOrHtqUiBDvmS17lm0xMGKT3Pf/lrWGer+aIBqL
ZC5mq9Ck8T+kzB9klfUidngouJQxrTakcnkWQVnmWWbCLXIvCdsyHwNjmZjMskrXfk7XPLI1C1X9
Nsw6Yrwc5xTnNyWdVKxyRTONSYjo0whQPtIphGYRboumFG/2Rd9DRtG7PKNLoyhlcJsWfvZS5Mes
NOmn6S9Zoo8e/RjmBTBQM4wVnVpNa2xsFxrWpQcJIKaxhGYgFMXXTx18y2VAbN2/tz3WE4KefJGj
00pdfUEZiMyY0e2V165OGi+96wDFbhq7T7pblOYD4rpcXutcukkkY/roqM9kQGt8vJG4sv2Vr1wX
APtSAOtOj2yuBi5aLvEcUG3+XjB4wMG7JvqrHywBKC2ycyd4DRCpDCIGBZvHynzDtnPbdHHRij0S
Yn+PasRiWPf2VpxfqbDSDpxfNS27AByi9u+Vw7Opgs/lXwJzZITcePsFdojq/b7/+Ucv78PjjMK2
ZEAxXlEG7PEMc/fJwub3Z2OkKvj6veID+PvYsVr98cpXAaTOFcgapT9P74mQ3/HZr3XwCAIxQ7xw
lM9QphPxYOHiBa+Bkt9elPHq+IPXSOcCGOs38RFTKBMGmO0qCVKfI2U89r9x8nJ00UxIiHMkPJme
keaaRekRA6jUOBB7FhJvMvqfuKX1xTc1jdLPiWW3nj73Y/DMhZ+WAAgHWCcThskfbxREtpgD75iW
XsbHF57GH9XoyQKd5iBPmElZxAUppU9K/CeHIM6gfVLcmcKxonk4tpy8Tdi5KivHv3k/c98+92mz
Yo6OegZsDy1+sOPDNvlPlfOpMcM8dKlqWXT+ztUjqYDsuHKtYFC6yjRRXdO4Qj60StfY0apn27az
/vHBGFF69uLPOc2iTdMeKXAgdG0ohOHMbPLkiW9zxLZXNcvOsZqDdXaKxrYF9LXrB4rFYRGEHwrQ
zvWFuFGE8dmZzQl9aSwUq2i7h/iioCk+ijRRoSKUpj7U0iK310oRrb270hYrtsnV/6LkWgu1p3T3
FPtwinen4B+wJH2xIEq3qE+ibn2wlYK3ikrpXXb9vt2ZZLLZXJLbXNvTDITdzezOfLPfb775/s12
1mcpfKaB1E7O3bNCFEZBmWFwZDZlbHjmqyMm6Zb/EDgCQBQqJoscGJ9LYU1tTwI4BgEcOQAGIQAU
j/pHx2Vqf/nkS5Nd9ixWcASgmODOQCsOEYl7dyUJY4bLWJYAQDwAiouAoTRDPj5Q6rJpMYED7XSM
/ccERZ00eXB/0qWsCNIjRXxwoCRhJfL+nkyXVdc6OAJpodeFGDpdHn45D6DIIUAY/GDZsWfe2TGn
ordi+DO0iHMdpcPzbPiViOuOgbVeurJ9gxHrudj3lOd5k789v85pMn6v8+AIpECUBW9zi1l23a8i
1TDoFAkc5/ZC4INtOZSnqI+oABDqA8T6a3Rbw4091z8x1nkGRTg1yuVy5s9jW62r0Dfg1DOdo3p/
g/EvCDjCjba/uyqQKGmFUg0sD8c9+1ZHrI4l20YnABRZVUgQSocuHt4SKbWUja/VMcgb3x1L4aab
RzTPdQswe7O1kxr0rPHdI1ejb79t1+0lH+y1Q+Ov27MDNOTj0ICOUZNIyVu+ZIjKeq0CAf10xZCp
anGiM953xx1pG59cTG7NtCxpenp6hgEUWbRmFAakqgwZEAkOGhFgLccEp3tiEGndwO7fZ8A0kt/R
+rJEx0L2Tdc+m1TK5fCGccwFySz0+DEgjdF3dJQa/L8g9He7vprHWnWpzmngvxjiMQ1DbNSOKOgB
P8OljMmfcaQdD5q0nGHkzwIRai3fNV5SVJZWfHOXJVcc+CR94eBD9ev/79ONZ+Gdj6Wa+l1qXDAK
muVLQVRl4UIj09Ph+uFW+45dzl8ALqnN72tAA0ttL86n27I1mhEBetNnWG0K6BkpayEKGBkOiLxf
V5v3jqVEgmxmw287CJjnufTReftaBF0ar8P+Msp1PbbiSw4Eh4pmborURyBI+dKlxrNwdlb4YeKW
yUr8vcW+Y7gKcJw5oD1LZmfDtf2t0lC+fDk9f8khl0CKnItQrixSFWOIxGBpCcLBaX6/yc3bkjTA
vD8Q2TFW3UYYnsm1+6iCl2M4p79MLbvvAd9JpsAMAiU1OY9xIkhPtfnMmghAZbmO1tvy8jjPj280
KKbPo/ZKJj44gtQ/pzLDg9nt+DNfUVIKo9PAGAdE+1D5m6MmZ16Wv8BoouX0mmhdJRoYwbMIyNXL
tnxRBH0jjcAggQRp3ynWotd2DgbLuyIJl4ZXwveC7+BQLPpbieY3BUfYd1ElyHdj07sfz3NXt8Hu
GTQ8xmxgVv9M8dW85BhL1oEkAEWBS5C24rM3vnIKQZnG5QTB4f7zN/l1zMRkPXuhTOgQ7QiIqI08
U20wp9UNDbJuJ4ovPf3lPS7AF9wJxksivSfvMjbggYhHVzcAxZco5KP9QqIkuT6SjoPcmwqnDQCF
jr4OLjlGftl6xxB/memIJWzB/Rxc17JCjK3vu1VQtGYNNl9WOrt8zR8cNWXdQZjZrEAoS3GxT6iq
mmCCDl8ee3Les/vmI19nQWpMoAmrJFR0gjk0kegF6TWhKGTDDxtXOU0ZFL+UuGifO1TQSXDU+o6E
fkcidUDZ3XC1wJHI7E3D8tGSBEg8ekRnqgrLD9XQswnnRGVsEph86OLIppbauOXNM+hQK/oKqBos
KXC9+sdNvT6Dbhs/hymAmEBSae+pnUOaZGlZfJZrbxwumKIOzvNwrpPave/4qZM8b0OXTGqT3yPf
65DqXhNdmt0l6Z4ST3CT6bElN8Ek/9/mfZs8Gc6WaJe/+pCW6MY2Hbge4dfiHj1MQ2gplK/D4xLJ
dmlOy6AYl9oKsxAYdO3+gvv5c01TH2fe3WHOSJt1lg+cQGWyD2z14g3PTAUmabBEmPD/1PmnMzWh
+ZVvf5sFIEz4ji/cPIhHRckAEKwakzKYVTK4da4fiA8Biu/TmPyl5mDgI6SaIZiTQCRKX+gFi8S6
HFdAse5n/pzNrSDhRxiQ/hcmeY63s5RUv1kwwOtQ/5oGmgpCr+P0ioQ+8QEHpNt3vPFMSkP6vB4J
WX4yDeHx5SSgyuOyRF/Qbh+/HzdnF9sTfetfMMCkHCYf7oulDK548SQommofLBdZEC0aSwSWCBVg
UOGoMpFwuIETjIy5S5pVNQmIfKZqfDbizJUdXzapZmtaUO9AvSw5SryNlPQyNVLN8hTSxH+W3ysy
wmUw+H3BPbZUT6Q2K21L0kU+F4BIESntntcnQ/SLvsVHL+yQI1EL6UpEalselyW9N0seV/vr4iOv
68DAAcbUDEgJpxNr26rj3xvQpq7wJYQGoJgMMUYMDj89YNbpHN1ybVgrWJZsO2ZQyrKgU/T/cVRv
O2tr5ejZQQzLw/PJitIZgGLRZ+X+78FR0Sl2vpcFHcIAXSIJR0dB5VNNnPOTdFQMtasaHDVYPtZQ
HiPBZYNx89RfQqi/V3UopFd0y2IHh1xuyH2aVDBYpbL1wHjUKzRSsTgCMMB5CbfRwW/sp823dsFw
DZd/Acb4Y7WK+XJUAAAAAElFTkSuQmCC

------=_NextPart_000_00EF_01D11222.DE17BA20--


From nobody Fri Oct 30 18:01:23 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17FB91ACDE5 for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level: 
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9-XWzjxeVHfS for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:20 -0700 (PDT)
Received: from shetland.sei.cmu.edu (shetland.sei.cmu.edu [192.58.107.44]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 531711ACDE1 for <dots@ietf.org>; Fri, 30 Oct 2015 18:01:20 -0700 (PDT)
Received: from timber.sei.cmu.edu (timber.sei.cmu.edu [10.64.21.23]) by shetland.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9V11Jkr009584 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:19 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1446253279; bh=tuIklDPwpsl78at6EzIAJqowtqH25f5TVk2DxnzQxoY=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=QwnMBxyaFQ52kCkpP5yGZlV6yIZynntW4uTmdkLAcb53aiA5EzKhvBRn4TsPPVOK3 vUE6LrAwMYSdRkfb+wvEJXHOTONerN+giQaLtbYy+1LUowY4RXz6c2f/eTm48VBx/y XBlaf46sgdIkRKLCErUS5Djuof4UX7fK1S45fLRg=
Received: from CASSINA.ad.sei.cmu.edu (cassina.ad.sei.cmu.edu [10.64.28.249]) by timber.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9V11GVX029701 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:16 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASSINA.ad.sei.cmu.edu ([10.64.28.249]) with mapi id 14.03.0248.002; Fri, 30 Oct 2015 21:01:16 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: draft-ietf-dots-use-cases-00 questions/comments
Thread-Index: AdETNjffB79LUO/+QGqNj8KfAZt1QA==
Date: Sat, 31 Oct 2015 01:01:15 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD95473FE@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/dmnXhY57FISry9HdX2XkydJf2PI>
Subject: [Dots] draft-ietf-dots-use-cases-00 questions/comments
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Oct 2015 01:01:22 -0000

Hello Roland, Stephane, Daniel, Robert, Nik and Frank!
=20
 [Note: This note is written as an individual contributor.  Chair hat off.]

Thanks again for preparing this initial WG draft of use cases.  In reviewin=
g draft-ietf-dots-use-cases-00, I had the following questions and comments.

** Page 4: Section 3: Terminology: I'm not sure where the canonical termino=
logy list should be.  I noticed a definition for "DDoS", "attack target" an=
d "Countermeasure" were added to those already in draft-ietf-dots-requireme=
nts-00.  Also the following are defined "attack telemetry" and "mitigation"=
 differently.  It would be helpful if the drafts coordinated in their langu=
age.

** Page 4: Section 4: Use Cases: "It should be noted that DOTS servers ... =
then initiate DDoS mitigation service by communicating directly or indirect=
ly with a DDoS mitigators". =20

To clarify, does "indirect communication" mean through a DOTS relay (i.e. c=
lient->server->relay->mitigator)?  I ask because draft-ietf-dots-requiremen=
ts-00 defines a relay as something between a client and server.

** Page 6: Section 4.1.1: step (d): "The DOTS servers ... determine that th=
ey have been to honor requests ..."  There appears to be a word or phrase m=
issing to the effect of the DOTS server determines whether it can or should=
 honor the request.

** Page 8: Section 4.1.2: Between steps (a) and (b).  How does the network =
infrastructure element know to use its DOTS client functionality?  The use =
case in Section 4.1.1 explicitly had a detection phase in step (b).  Doesn'=
t this use case need that too?

** Page 9: Section 4.1.3: same feedback as above.

** I liked the way the explicit steps were written up.  All of the introduc=
tions for 4.1.* were helpful.  By the time I got to 4.1.3, I noticed that t=
he text for each of the steps was nearly identical to the previous section =
other than to replacement of the type of DOTS client (i.e., CPE vs. network=
 infrastructure element).  For readability, I think it would be clearer to =
see the differences in the use cases if the common steps just referenced pr=
evious text.  For example, Section 4.1.1a =3D 4.1.2a; 4.1.1c =3D 4.1.2b, et=
c.

** The implicit protocol I got out of Section 4.1 was:
* Mitigation Service Initiation (step b per Section 4.1.1)
* Service Status Message (step d per Section 4.1.1)
* Efficacy updates (step f per Section 4.1.1)
* Mitigation Status Update (step h and k per Section 4.1.1; step f of Secti=
on 4.1.7)
* Mitigation Service Termination Request (step i per Section 4.1.1)
* Mitigation Termination Status Acknowledgement (per l per Section 4.1.1)

Regards,
Roman


From nobody Fri Oct 30 18:01:24 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FE1D1ACDE1 for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level: 
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7cXxJUCvCEkG for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:20 -0700 (PDT)
Received: from plainfield.sei.cmu.edu (plainfield.sei.cmu.edu [192.58.107.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52F6E1ACDE0 for <dots@ietf.org>; Fri, 30 Oct 2015 18:01:20 -0700 (PDT)
Received: from timber.sei.cmu.edu (timber.sei.cmu.edu [10.64.21.23]) by plainfield.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9V11JDA028569 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:19 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1446253279; bh=M3jVWJoTLko6Gwy6iSlTiB+6I8M0gzwnUrVfT0Z5LtA=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=KpqNlSC503bKy6rJgR4KS8XGDv6FXzCiel5P/NJczNtjR2NnsaTUgBhRwgdAbLAWg 7ISQmEeOUNabafNe6xLy9DLbgYQxwp3zySOGTbT2+fLIcSjzQpoUc2a0K9hL10Vwx6 9nc8PXHhYrLjh6Fay7tKS9diRsIJ4IyMvkxT1c0A=
Received: from CASCADE.ad.sei.cmu.edu (cascade.ad.sei.cmu.edu [10.64.28.248]) by timber.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9V11Els029694 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:14 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASCADE.ad.sei.cmu.edu ([10.64.28.248]) with mapi id 14.03.0248.002; Fri, 30 Oct 2015 21:01:14 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: draft-reddy-dots-transport-01 questions/comments
Thread-Index: AdESzrt3abkfTKpBT2qmQFMcQzRfng==
Date: Sat, 31 Oct 2015 01:01:13 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD95473F4@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/IawhQxpkGGhUPOE3RaWohw6fOEM>
Subject: [Dots] draft-reddy-dots-transport-01 questions/comments
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Oct 2015 01:01:22 -0000

Hello Tiru, Dan, Prashanth, Mike, Mohamed and Robert!

[Note: This entire message is written as an individual contributor.  Chair =
hat off]

In reading draft-reddy-dots-transport-01, I had a few questions and comment=
s.  Given that this is an early -01 draft, I readily acknowledge that it mi=
ght be premature to broach them so please defer as necessary.

** Page 5, Section 4.1.1: policy-id: "This identifier must be unique for ea=
ch policy bound to the DOTS client."
I had difficulty understanding what this sentence meant.  Is this uniquenes=
s property the same as saying that (a) every distinct SOS request needs a u=
nique policy-id? (b) this policy-id needs to be unique relative to the acti=
ve requests with the DOTS server?  The text clearly states that the "docume=
nt does not make assumption about this identifier is generated" but are any=
 assumptions made about the state kept?

** Page 5, Section 4.1.1: target-ip and target-port: Each of these fields c=
an take a list.  What is the format of that list?  Figure 7 for example sug=
gests that ranges are possible (e.g., 1-65535).

** Section 4 presents a RESTful API.  However, the current text only descri=
bes the request.  What do responses look like?  Does the client get back a =
200 code on success?  What does the server return when an unrecognized poli=
cy-id is passed when trying to retrieve the active SOSes?  How are unrecogn=
ized fields treated? =20

** Page 6, Section 4.1.1: Signal SOS: "... thus sending a maximum of 500 by=
tes of SOS message ..."
What happens if the SOS message needs to be more than 500 bytes?  Perhaps t=
he request has a really long URL and a number of individual IP addresses th=
at aren't aggregated.  Does the request then need to be split into separate=
 SOS messages?

** Page 6, Section 4.1.1: Signal SOS: How should multiple instances of any =
of the fields be parsed (e.g., multiple target-ip or policy-id)?

** Page 7, Section 4.1.2: Retrieving SOS: What does a response look like wh=
en retrieving a specific SOS?  Is it an HTTP response with the body of the =
JSON that made the request? =20

** Page 7, Section 4.1.2: Retrieving SOS: What does the response for all SO=
S look like?  In what order are they returned?

** Page 7, Section 4.2: REST: This introductory section explicitly referenc=
es a DOTS client, relay and server.  Can there just be a client talking to =
the server?

** Page 8, Section 4.2.1.1: Install filtering rules: Are any of the describ=
ed fields are optional?

** Page 9, Section 4.2.1.1: lifetime: "Upon expiry of this lifetime, and if=
 the request is not reiterated, the rule will be withdrawn ..."
How is a request reiterated?  Just resend the same message? =20

** Page 9, Section 4.2.1.1: lifetime: What happens if a message is "reitera=
ted" without being expired.  For example:
Send: (time=3D0; policy-id=3D1; lifetime=3D100)
Send: (time=3D10; policy-id=3D1; lifetime=3D100)

At time=3D10 what is the value of the lifetime counter for policy-id=3D1?  =
Is it 90? Or 90+100?

Regards,
Roman


From nobody Fri Oct 30 18:01:33 2015
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E2B11ACDE0 for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.7
X-Spam-Level: 
X-Spam-Status: No, score=-3.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, J_CHICKENPOX_64=0.6, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jAPARlD3o8ix for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:01:22 -0700 (PDT)
Received: from plainfield.sei.cmu.edu (plainfield.sei.cmu.edu [192.58.107.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5CA561ACDE4 for <dots@ietf.org>; Fri, 30 Oct 2015 18:01:21 -0700 (PDT)
Received: from pawpaw.sei.cmu.edu (pawpaw.sei.cmu.edu [10.64.21.22]) by plainfield.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id t9V11Kgp028574 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:20 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1446253280; bh=EZcw3rQgZifW7EEVRZRd2I2y5NTBOqQZB+1pQrpwiMc=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=KBl01O8Bua8QkhECQ2O0AzeyfqwwgO3fqii9reFqeGHWZ5CBLim4czh3CkCpGw/Zf XgXgAcpAmZT3NzBROWnawPXGzduXRJnRP+ZY1C9MJ7Uflxoq2jEw6cbfD1YC1uprdo X9a1wu51r2C05lYX8FSGls/P/LV9Wc1jNUDuOCPI=
Received: from CASCADE.ad.sei.cmu.edu (cascade.ad.sei.cmu.edu [10.64.28.248]) by pawpaw.sei.cmu.edu (8.14.4/8.14.4/1456) with ESMTP id t9V11Teu025076 for <dots@ietf.org>; Fri, 30 Oct 2015 21:01:29 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASCADE.ad.sei.cmu.edu ([10.64.28.248]) with mapi id 14.03.0248.002; Fri, 30 Oct 2015 21:01:19 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: draft-ietf-dots-requirements-00 questions/comments
Thread-Index: AdES07Pd2stjvZZVQYOPK8fHqTIdgA==
Date: Sat, 31 Oct 2015 01:01:17 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFCD9547406@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/042uEdLpdxTCtaBBGVBRoebeBu0>
Subject: [Dots] draft-ietf-dots-requirements-00 questions/comments
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Oct 2015 01:01:23 -0000

Hello Andrew, Robert and Tiru!

[Note: This note is written as an individual contributor.  Chair hat off.]

Thanks again for preparing this initial WG draft of the requirements.  In r=
eviewing draft-ietf-dots-requirements-00, I had the following questions and=
 comments.

** Page 3: Section 1.1: Overview: "To achieve this aim, the protocol must p=
ermit DOTS clients ... to set the scope of the mitigation ...; and supply s=
ummarized attack information and additional hints the ...".
 =09
OP-006 aligns with the "set the scope of the mitigation".  DATA-004 aligns =
with the "summarized attack information".  My question is whether "summariz=
ed attack information" should be restricted to only white and black lists (=
DATA-004).  Do we need other attack information ("attack telemetry")?

** Page 3: Terminology: I'm not sure where the canonical terminology list s=
hould be.  I noticed that draft-ietf-dots-use-case-00 includes a definition=
 for "DDoS", "attack target" and "Countermeasure" not present in this draft=
.  It also defines "attack telemetry" and "mitigation" differently.  =20

** Page 6: General Requirements: G-004 and G-005 appear to only apply to th=
e signal channel.  Since there is a Data Channel Requirements section (Sect=
ion 2.3), it seems like there should be corresponding Signal Channel requir=
ements one as well.  With G-003, "signaling protocol" is used to scope the =
requirement.  Is that the same as "signal channel" or "DOTS signal" (i.e., =
signal+data channel)?

** Page 7: G-006: In order for DOTS ... despite advancements in cryptanalys=
is ...".  I'd recommend a broader statement.  Minimally, "... despite advan=
cements in cryptanalysis and traffic analysis".

** Page 7: G-007: " ... such as including a timestamp or sequence number in=
 every heartbeat and signal sent between DOTS agents."  I would recommend r=
emoving this last clause.  IMO, it is too specific and implementation orien=
ted.  The requirement articulated in the first part of the sentence is clea=
r enough.

** Page 7: G-008: This requirement appears to only apply to the Data Channe=
l.  IMO, it would fit better in Section 2.3, the section for data channel r=
equirements.

** Page 7: G-008: "As the resilience requirements for DOTS mandate small ..=
.".  I propose this sentence read "As the resilience requirements for the D=
OTS signal channel mandates ..." to highlight that the signal and data chan=
nels have different requirements.

** Page 9: DATA-002: How is this requirement different than G-006?  It has =
more specificity on why integrity and confidentiality are important for the=
 data channel, but it still just repeats that encryption and authentication=
 is required.

** Page 10: DATA-003: How is this authentication clause of this requirement=
 different than OP-002? DATA-003 does add an authorization requirement not =
present in OP-002.

** In considering the ancillary used cases in draft-ietf-dots-use-cases-00,=
 OP-006 would likely cover at least some of the Provisioning Use Case (Sect=
ion 4.2.2).  I didn't see a requirement covering the Registration Use Case =
(Section 4.2.1).

Regards,
Roman


From nobody Fri Oct 30 18:34:33 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C91D1ACEBF for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:34:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hVvScwJTMw9K for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 18:34:30 -0700 (PDT)
Received: from mail-pa0-x22e.google.com (mail-pa0-x22e.google.com [IPv6:2607:f8b0:400e:c03::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DC4E91ACEBD for <dots@ietf.org>; Fri, 30 Oct 2015 18:34:29 -0700 (PDT)
Received: by pasz6 with SMTP id z6so89160517pas.2 for <dots@ietf.org>; Fri, 30 Oct 2015 18:34:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-type; bh=8jb5zmcGUFqgpUvrCJ85HJcz78UuwijsVR4TEnjrnqc=; b=lQBivy/2meeHIAPfxBTO3Utb+q9X6kcqfUFBozvWGHbBfDlpXVDGzxZjG6ukmvLaAJ VeDbaqxprJck0eqc3hgAr5rY8exfcjlY8yztnN8UuZkS1XaWBKzDdav1dLSRjQf4lpAH rrDaxGqAid9WtOBMIbU7wMhwq2n5W+pbTRl9Y=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=8jb5zmcGUFqgpUvrCJ85HJcz78UuwijsVR4TEnjrnqc=; b=MJU7JFy5xvhr4DvXp3WpzYRsSvJHJnmwFwufN58+VzlTniQ7KV1woBI5r1O0TTfWD3 o07iYEtPRxD3Pv3CiMpZgqOah6bW4jD74E8pPZO67JCP2sSxvpm+yItotdl+Nw9zFTma qXHrNjRT4g15R/ivntgTDSkXioem1WJE21jhU+pgK0KY8xgsRmnCSw89XSU/E+ABkGO3 k/5mucmLVhRvjv1wB0HI39aFK1OCsq+I31i2j61YV2tHPUjsDSOID2DMe6jkLfUQq5wu W1Hs85uwm626lgYsqQw8JJrmPwcoTiR+A1/69uzZcccnG1FzoZZ2mATFr2wXLEsoGffv CLjw==
X-Gm-Message-State: ALoCoQlhqUYN1j39wM6p/WpN5GAexQfOniAzBwcQ5fONKJKT6FBUReDlLXRLj8oP/QMoe+prcZnk
X-Received: by 10.66.120.136 with SMTP id lc8mr12107296pab.19.1446255269499; Fri, 30 Oct 2015 18:34:29 -0700 (PDT)
Received: from [10.0.1.3] (p5231-ipngn5001hodogaya.kanagawa.ocn.ne.jp. [153.220.164.231]) by smtp.gmail.com with ESMTPSA id fx3sm10508147pbb.60.2015.10.30.18.34.28 (version=TLSv1 cipher=RC4-SHA bits=128/128); Fri, 30 Oct 2015 18:34:28 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: dots@ietf.org
Date: Sat, 31 Oct 2015 10:34:26 +0900
Message-ID: <5A2C39C3-F2D8-41E5-948E-99D9786EAB16@arbor.net>
In-Reply-To: <00ee01d11244$65295a20$2f7c0e60$@br-envision.com>
References: <005b01d10cc8$cdbc0960$69341c20$@br-envision.com> <D253AE4C.383AB%stefan.fouant@corero.com> <00ee01d11244$65295a20$2f7c0e60$@br-envision.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/iPjX0kzhKxAFQcVzXHAM-81m82k>
Cc: Harley Green <harley@br-envision.com>
Subject: Re: [Dots] DDoS-Alert BGP Extensions
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Oct 2015 01:34:31 -0000

On 29 Oct 2015, at 21:21, Harley Green wrote:

> You are absolutely correct that the large network providers are going 
> to
> resist any sort of technology change for security's sake, as they are 
> not in
> the business of DDoS mitigation,

I've a lot more comments on this draft and will post them later, but I 
would like to point out that *all* the large network providers are in 
the business of DDoS mitigation.

So, I think perhaps it's worth ensuring that everyone engaged in 
thinking about this general space understands that, as it's foundational 
to positing worthwhile innovations in this space.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>


From nobody Fri Oct 30 23:37:20 2015
Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D21111B351B for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 23:37:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fDrioIEbi0ug for <dots@ietfa.amsl.com>; Fri, 30 Oct 2015 23:37:17 -0700 (PDT)
Received: from mail-pa0-x22c.google.com (mail-pa0-x22c.google.com [IPv6:2607:f8b0:400e:c03::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32F281B3518 for <dots@ietf.org>; Fri, 30 Oct 2015 23:37:17 -0700 (PDT)
Received: by pacfv9 with SMTP id fv9so98197390pac.3 for <dots@ietf.org>; Fri, 30 Oct 2015 23:37:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arbor.net; s=m0; h=from:to:subject:date:message-id:in-reply-to:references:mime-version :content-type; bh=YA87IBndvnNgfNKXJaHBOyPVZnqMPcBTpmE/sJF0ai0=; b=VHR5pArD+CkBxGLTFz+2BIn19MtB5mtJR33V4/crNikAB7P3zxSHRkIQlQCifLZ+uB tEJD9bBLM1vqiKTXsmVfUBysvBTYEX9IMidWNMt/+KrLf1PUfFz5l4NV+N8EziGSu8dS 8WJUlvrcOkzdnh45deHXYjP0+CvF10MHzvE9U=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to :references:mime-version:content-type; bh=YA87IBndvnNgfNKXJaHBOyPVZnqMPcBTpmE/sJF0ai0=; b=OW6RI0l5UP3JrBrAwgGxqbXIQWnWJZnuBRovmPbHo3M/mmM3dwGD95zxgIEwbr34Rw IIp5toUP64C2iXlhSTOFOT+atdjE0WIomJe2GGr6w3ttVjY6kLAM2w914eKk1T4WoyoJ inJJgxxpWgsauCAdM1M4HIPfCoWmbI1XfGrmNCxWbiwQAb3vYmVNamk2J4MJSJL30DGq VfADRnHH9Hg204+gXWC5j7thU4JY6q3U284oqz+I3UTzUX2lK5k9uL420DUCIWIDUfiN UwyBD4n+JgwTdc4IsGq2uH1sgeB1N4zAaCTy8jipLal1U65u4lwU3mFSP1zFGl21OqCj 9Dvw==
X-Gm-Message-State: ALoCoQkUB83e3VvK/SelIreOWZr6otmgap+8KQwUxWamEv/JppKXvlA6kYfc+q9sM51h8T03ihxw
X-Received: by 10.68.213.198 with SMTP id nu6mr13163492pbc.96.1446273436772; Fri, 30 Oct 2015 23:37:16 -0700 (PDT)
Received: from [10.0.1.3] (p5231-ipngn5001hodogaya.kanagawa.ocn.ne.jp. [153.220.164.231]) by smtp.gmail.com with ESMTPSA id rx10sm3144087pab.21.2015.10.30.23.37.15 for <dots@ietf.org> (version=TLSv1 cipher=RC4-SHA bits=128/128); Fri, 30 Oct 2015 23:37:15 -0700 (PDT)
From: "Roland Dobbins" <rdobbins@arbor.net>
To: "dots@ietf.org" <dots@ietf.org>
Date: Sat, 31 Oct 2015 15:37:13 +0900
Message-ID: <FD898A8D-EFAC-4459-A088-39679C6C76E6@arbor.net>
In-Reply-To: <359EC4B99E040048A7131E0F4E113AFCD95473FE@marathon>
References: <359EC4B99E040048A7131E0F4E113AFCD95473FE@marathon>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
X-Mailer: MailMate (1.9.2r5141)
Archived-At: <http://mailarchive.ietf.org/arch/msg/dots/iCqp9C_4c8me3ylsWCi5yYhXQ-Q>
Subject: Re: [Dots] draft-ietf-dots-use-cases-00 questions/comments
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Oct 2015 06:37:19 -0000

On 31 Oct 2015, at 10:01, Roman D. Danyliw wrote:

> ** Page 4: Section 3: Terminology: I'm not sure where the canonical 
> terminology list should be.  I noticed a definition for "DDoS", 
> "attack target" and "Countermeasure" were added to those already in 
> draft-ietf-dots-requirements-00.  Also the following are defined 
> "attack telemetry" and "mitigation" differently.  It would be helpful 
> if the drafts coordinated in their language.

Yes, we need to reconcile them.  The differing definitions were placed 
in draft-ietf-dots-use-cases-00 to point out the need for 
reconciliation.
>
> ** Page 4: Section 4: Use Cases: "It should be noted that DOTS servers 
> ... then initiate DDoS mitigation service by communicating directly or 
> indirectly with a DDoS mitigators".
>
> To clarify, does "indirect communication" mean through a DOTS relay 
> (i.e. client->server->relay->mitigator)?  I ask because 
> draft-ietf-dots-requirements-00 defines a relay as something between a 
> client and server.

This communication is out of the scope for DOTS - generally a 
proprietary mechanism, paradigms vary greatly.  This is one of the 
primary reasons we need DOTS.
>
> ** Page 6: Section 4.1.1: step (d): "The DOTS servers ... determine 
> that they have been to honor requests ..."  There appears to be a word 
> or phrase missing to the effect of the DOTS server determines whether 
> it can or should honor the request.

Yes, type - should be 'configured'.  Will be corrected in -01.
>
> ** Page 8: Section 4.1.2: Between steps (a) and (b).  How does the 
> network infrastructure element know to use its DOTS client 
> functionality?  The use case in Section 4.1.1 explicitly had a 
> detection phase in step (b).  Doesn't this use case need that too?

It does; if we need to spell it out again for the sake of clarity, we 
can do that in -01, no problem.
>
> ** Page 9: Section 4.1.3: same feedback as above.

Same as above, if we need to spell it out again, we can in -01.

>
> ** I liked the way the explicit steps were written up.  All of the 
> introductions for 4.1.* were helpful.  By the time I got to 4.1.3, I 
> noticed that the text for each of the steps was nearly identical to 
> the previous section other than to replacement of the type of DOTS 
> client (i.e., CPE vs. network infrastructure element).  For 
> readability, I think it would be clearer to see the differences in the 
> use cases if the common steps just referenced previous text.  For 
> example, Section 4.1.1a = 4.1.2a; 4.1.1c = 4.1.2b, etc.

Concur.  This repetitive text was a deliberate editorial decision for 
-00 so as to ensure that we're all clear that there's a high degree of 
commonality in the ebb and flow of DOTS communications under 
circumstances which appear to be very different from a topological and 
functional perspective, but in reality are pretty close at at abstract 
level.

We'll remove all the repetitive stuff and replace it with callbacks and 
diffs in -01.
>
> ** The implicit protocol I got out of Section 4.1 was:
> * Mitigation Service Initiation (step b per Section 4.1.1)
> * Service Status Message (step d per Section 4.1.1)
> * Efficacy updates (step f per Section 4.1.1)
> * Mitigation Status Update (step h and k per Section 4.1.1; step f of 
> Section 4.1.7)
> * Mitigation Service Termination Request (step i per Section 4.1.1)
> * Mitigation Termination Status Acknowledgement (per l per Section 
> 4.1.1)

Yes, that's pretty much it, in a nutshell.  Status messages, efficacy 
updates, termination requests, and acknowledgement thereof are all 
desirable from the standpoint of each participating element and 
organization understanding the current state of play, but are not 
required in order for mitigation to be initiated, to be maintained, 
and/or to be terminated.  They're useful, but optional in terms of 
actually making things happen.

The language will be wordsmithed in -01, as well.  It was imperative to 
get something which was essentially 'feature-complete' out the door for 
discussion on Tuesday, but we'll refine and streamline the language as 
we take on board feedback from WG participants and incorporate it into 
-01.  So, -01 will be a substantial stylistic rewrite, as well as 
incorporating WG feedback.

Good feedback, thanks much!

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>

