From exim@www1.ietf.org  Thu Jul 10 13:59:01 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14560
	for <rpsec-archive@odin.ietf.org>; Thu, 10 Jul 2003 13:59:01 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19afgh-0007sf-CJ
	for rpsec-archive@odin.ietf.org; Thu, 10 Jul 2003 13:58:35 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6AHwZJe030287
	for rpsec-archive@odin.ietf.org; Thu, 10 Jul 2003 13:58:35 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19afgh-0007sQ-8B
	for rpsec-web-archive@optimus.ietf.org; Thu, 10 Jul 2003 13:58:35 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14542
	for <rpsec-web-archive@ietf.org>; Thu, 10 Jul 2003 13:58:30 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19afge-0005ir-00
	for rpsec-web-archive@ietf.org; Thu, 10 Jul 2003 13:58:33 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19afge-0005in-00
	for rpsec-web-archive@ietf.org; Thu, 10 Jul 2003 13:58:32 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19afg8-0007nT-PG; Thu, 10 Jul 2003 13:58:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19affl-0007my-Gx
	for rpsec@optimus.ietf.org; Thu, 10 Jul 2003 13:57:37 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14510
	for <rpsec@ietf.org>; Thu, 10 Jul 2003 13:57:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19affi-0005iC-00
	for rpsec@ietf.org; Thu, 10 Jul 2003 13:57:34 -0400
Received: from mesa.bbnplanet.com ([171.78.172.21])
	by ietf-mx with esmtp (Exim 4.12)
	id 19affh-0005hd-00
	for rpsec@ietf.org; Thu, 10 Jul 2003 13:57:34 -0400
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6AHv2P02062
	for <rpsec@ietf.org>; Thu, 10 Jul 2003 13:57:02 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Thu, 10 Jul 2003 13:57:01 -0400 (EDT)
From: Tony Tauber <ttauber@genuity.net>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: rpsec@ietf.org
Message-ID: <Pine.GSO.4.56.0307101350360.23713@mesa.bbnplanet.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] RPSEC meeting cancelled in Vienna
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Greetings all,

Due to the fact that there's been no appreciable movement lately on
either the Threats or Requirements documents which are our charter
deliverables, and there have been no requests or suggestions for
presentations or discussions in Vienna, the WG won't bother to
meet there.

If there are things that people would like to discuss; please advise
ASAP (As Soon As Possible).

Thanks,

Tony

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Fri Jul 11 13:53:51 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA08158
	for <rpsec-archive@odin.ietf.org>; Fri, 11 Jul 2003 13:53:51 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19b25E-0007AC-9y
	for rpsec-archive@odin.ietf.org; Fri, 11 Jul 2003 13:53:24 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6BHrOwN027535
	for rpsec-archive@odin.ietf.org; Fri, 11 Jul 2003 13:53:24 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19b25D-0007A2-ST
	for rpsec-web-archive@optimus.ietf.org; Fri, 11 Jul 2003 13:53:23 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA08130
	for <rpsec-web-archive@ietf.org>; Fri, 11 Jul 2003 13:53:15 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19b256-00006S-00
	for rpsec-web-archive@ietf.org; Fri, 11 Jul 2003 13:53:16 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19b255-00006P-00
	for rpsec-web-archive@ietf.org; Fri, 11 Jul 2003 13:53:15 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19b24r-00077D-FC; Fri, 11 Jul 2003 13:53:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19b23s-0006wR-Nl
	for rpsec@optimus.ietf.org; Fri, 11 Jul 2003 13:52:00 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA08072
	for <rpsec@ietf.org>; Fri, 11 Jul 2003 13:51:56 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19b23p-00004e-00
	for rpsec@ietf.org; Fri, 11 Jul 2003 13:51:57 -0400
Received: from kanfw1.ottawa.alcatel.ca ([192.75.23.69] helo=kanmx1.ca.alcatel.com)
	by ietf-mx with smtp (Exim 4.12)
	id 19b23o-00004S-00
	for rpsec@ietf.org; Fri, 11 Jul 2003 13:51:56 -0400
Received: (qmail 15118 invoked from network); 11 Jul 2003 18:02:12 -0000
Received: from unknown (HELO CAOTTM00147) (138.120.62.35)
  by kanmx1.ca.alcatel.com with SMTP; 11 Jul 2003 18:02:12 -0000
Message-ID: <021001c347d5$0b58c900$233e788a@CAOTTM00147>
From: "Emanuele Jones" <emanuele.jones@alcatel.com>
To: <rpsec@ietf.org>
Date: Fri, 11 Jul 2003 13:51:19 -0400
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_020D_01C347B3.81776730"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
Subject: [RPSEC] OSPF vulnerabilities draft
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

This is a multi-part message in MIME format.

------=_NextPart_000_020D_01C347B3.81776730
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Greetings,

I would like to introduce a new Internet Draft: =
draft-jones-OSPF-vuln-00.txt. This draft is now available at the IETF =
website.=20

I believe that even though the group has already moved to the developing =
of  a generic threat paper (draft-ietf-rpsec-routing-threats-01.txt), =
security of IGP has not been extensively covered and discussed as much =
as EGP's security was with BGP, SoBGP and SBGP. Thus, this paper may be =
a good occasion to initiate some work on that topic. This memo =
systematically dissects every message and every aspect of OSPF searching =
for vulnerabilities that could lead to insider, outsider or DoS attacks =
against the control and the data plane. The paper is more than just a =
literature survey about OSPF security; aside from discovering new =
vulnerabilities that came directly from the test bed, the draft =
highlights and describes a few "misconceptions" about OSPF's security =
such as "fight back" and remote attacker prevention.

The Internet Draft is available at: =
http://www.ietf.org/internet-drafts/draft-jones-ospf-vuln-00.txt


Regards,

Emanuele

Emanuele Jones=20
Alcatel Canada - R&I - Security group=20
600 March Road - Kanata, ON, Canada K2K 2E6=20
Phone: +1 613 784 5977 Fax: +1 613 784 8944=20
Email: emanuele.jones@alcatel.com=20
=20


------=_NextPart_000_020D_01C347B3.81776730
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 5.50.4807.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV align=3Djustify><FONT face=3DArial size=3D2>Greetings,</FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2>I would like to =
introduce a new=20
Internet Draft: draft-jones-OSPF-vuln-00.txt. This draft is now=20
available&nbsp;at the IETF website. </FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2>I believe that even =
though the group=20
has already moved to the developing of &nbsp;a generic threat paper=20
(draft-ietf-rpsec-routing-threats-01.txt),&nbsp;security&nbsp;of IGP has =
not=20
been extensively covered and discussed&nbsp;as much as EGP's =
security&nbsp;was=20
with BGP, SoBGP and SBGP. </FONT><FONT face=3DArial size=3D2>Thus, this =
paper may be=20
a good occasion to initiate some work on that topic. This memo =
systematically=20
dissects every message and every aspect of OSPF searching for =
vulnerabilities=20
that could lead to insider, outsider or DoS attacks against the control =
and the=20
data plane. The paper is more than just a literature survey about OSPF =
security;=20
aside from discovering new vulnerabilities&nbsp;that came directly=20
from&nbsp;the&nbsp;test =
bed,&nbsp;the&nbsp;draft&nbsp;highlights&nbsp;and=20
describes&nbsp;a few "misconceptions" about OSPF's security such as =
"fight back"=20
and remote attacker prevention.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>The Internet Draft is available at: <A=20
href=3D"http://www.ietf.org/internet-drafts/draft-jones-ospf-vuln-00.txt"=
><EM><FONT=20
face=3D"Times New Roman"=20
size=3D3>http://www.ietf.org/internet-drafts/draft-jones-ospf-vuln-00.txt=
</FONT></EM></A></FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial><BR><FONT =
size=3D2></FONT></FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2>Regards,</FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2>Emanuele</FONT></DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV align=3Djustify><FONT face=3DArial size=3D2>Emanuele Jones =
<BR>Alcatel Canada -=20
R&amp;I - Security group <BR>600 March Road - Kanata, ON, Canada K2K 2E6 =

<BR>Phone: +1 613 784 5977 Fax: +1 613 784 8944 <BR>Email: </FONT><A=20
href=3D"mailto:emanuele.jones@alcatel.com"><FONT face=3DArial=20
size=3D2>emanuele.jones@alcatel.com</FONT></A><FONT face=3DArial =
size=3D2>=20
<BR>&nbsp;<BR></DIV></FONT></BODY></HTML>

------=_NextPart_000_020D_01C347B3.81776730--


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 21:50:38 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA10982
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 21:50:38 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsTj-0004HK-PZ
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:50:11 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E1oBDt016440
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:50:11 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsTj-0004H5-9c
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 21:50:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA10970
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 21:50:07 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsTg-0000YJ-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:50:08 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsTf-0000YF-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:50:07 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsTZ-0004Fy-1d; Sun, 13 Jul 2003 21:50:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsT7-0004Fd-0m
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 21:49:33 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA10965
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:49:29 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsT4-0000YA-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:49:30 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsT3-0000Y4-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:49:29 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-3.cisco.com with ESMTP; 13 Jul 2003 18:52:45 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E1mvMK003218
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:48:58 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id VAA03592
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:48:56 -0400 (EDT)
Date: Sun, 13 Jul 2003 21:48:56 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
Message-ID: <Pine.WNT.4.55.0307132143380.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 1: Neighbors & Peers?
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I think the general concensus was to use neighbors, rather than peers, in
all of our working group docs to describe routers which have formed a
relationship? Is this correct?

If so, could the authors of the threats draft take note of this as
something that needs to be fixed up in the next version?

Thanks!

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 21:54:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11059
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 21:54:29 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsXS-0004PF-OM
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:54:02 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E1s2fa016931
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:54:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsXS-0004P0-KO
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 21:54:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11048
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 21:53:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsXP-0000ZG-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:53:59 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsXP-0000ZD-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:53:59 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsXR-0004Nu-CP; Sun, 13 Jul 2003 21:54:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsWy-0004NZ-LD
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 21:53:32 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11042
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:53:28 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsWv-0000Z4-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:53:29 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsWv-0000Z1-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:53:29 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-2.cisco.com with ESMTP; 13 Jul 2003 18:51:53 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E1qvMK003818
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:52:57 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id VAA03747
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:52:57 -0400 (EDT)
Date: Sun, 13 Jul 2003 21:52:56 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: rpsec@ietf.org
Message-ID: <Pine.WNT.4.55.0307132149410.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 2: Section 4.1 Deliberate Exposure
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I don't seem to recall a concensus being reached on the exposure of routing
information within the context of the threats draft--the last email I saw
on the topic was from Tony:

--
I'm confused as well.  The sense I take from "deliberate" is that it's
intentional.  If information is intentionally revealed to parties who
aren't authorized, it would seem to be a malicious act in itself,
perhaps meant to deceive?

Tony
--

What's the current status of this item? Is there a concensus on whether or
not the exposure of routing information is a threat to a routing system, or
not? I would think it could be, but only in terms of exposing topology
information to attackers outside the network, not insiders, since it would
be almost impossible to prevent this information from being known to anyone
within the network (with a network connection of any type).

Thoughts?

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 21:59:31 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11128
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 21:59:31 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bscL-0004Yd-0u
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:59:05 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E1x5X0017513
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 21:59:05 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bscK-0004YO-Sy
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 21:59:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11102
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 21:59:00 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bscH-0000aD-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:59:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bscH-0000aA-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 21:59:01 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bscH-0004XH-Hn; Sun, 13 Jul 2003 21:59:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsbW-0004Wr-W6
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 21:58:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA11097
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:58:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsbU-0000Zy-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:58:12 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsbT-0000Zp-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 21:58:11 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-2.cisco.com with ESMTP; 13 Jul 2003 18:56:36 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6E1veAi001953
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:57:40 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id VAA03982
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 21:57:39 -0400 (EDT)
Date: Sun, 13 Jul 2003 21:57:39 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132156410.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 3: Section 4.5 Underclaiming
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Did we come to some concensus on whether or not underclaiming is a
legitimate threat? I know there was a lengthy discussion on this, but I
don't recall any sort of final concensus around the question.

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:06:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11237
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:06:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsj6-0004mt-1q
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:06:04 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E264PI018375
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:06:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsj5-0004mI-TL
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:06:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11221
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:05:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsj2-0000cS-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:06:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsj2-0000cP-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:06:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsj3-0004l8-Qf; Sun, 13 Jul 2003 22:06:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsiK-0004kn-5X
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:05:16 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11218
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:05:12 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsiH-0000cK-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:05:13 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsiG-0000cH-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:05:12 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-3.cisco.com with ESMTP; 13 Jul 2003 19:08:28 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E24eMK005964
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:04:41 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA04240
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:04:40 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:04:39 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132200290.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 4: Section 3.1 Threat Sources
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


We don't seem to have gotten through a concensus on the threat sources
portion of the threats draft, specifically in the seperation of
unauthorized and masquerading threat sources. So, what I seem to have from
the thread is:

Sandy: We shouldn't consider masquerading and unauthorized as different
Russ: Define the ideas, but combine them throughout the draft as one
  problem

Others? I'm not certain where we are on this topic.

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:11:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11341
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:11:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsnv-0005BI-Pm
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:11:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2B3QB019910
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:11:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsnv-0005B3-Lk
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:11:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11331
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:10:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsns-0000eC-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:11:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsns-0000e9-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:11:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsnu-000593-AT; Sun, 13 Jul 2003 22:11:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsnN-00058o-Pa
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:10:29 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11328
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:10:25 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsnK-0000e6-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:10:26 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsnK-0000dq-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:10:26 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E29sMK006825
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:09:54 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA04567
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:09:54 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:09:53 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132208080.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 6: Section 4.7 Overload
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Sandy expressed some reservations about this section, stating that
overloading the control plane and overloading the data plane are two
seperate topics, and that routing protocol design could do little to help
in either of them.

Is there any concensus on this within the working group? I think we need
some more discussion, probably?

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:14:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11393
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:14:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsqq-0005JN-KC
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:14:04 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2E41g020411
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:14:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsqq-0005J8-G7
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:14:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11384
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:14:00 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsqn-0000f3-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:14:01 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsqm-0000f0-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:14:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsqn-0005H9-0n; Sun, 13 Jul 2003 22:14:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsqh-0005Gy-R3
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:13:57 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11381
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:13:51 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsqe-0000et-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:13:52 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bsqe-0000el-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:13:52 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2DKMK007394
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:13:20 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA04784
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:13:19 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:13:18 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132211230.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 6: Consistent Use of Blackhole
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Sandy brought up, some time back, that the term blackhole didn't appear to
be used consistently throughout the threats draft. Does the WG feel this is
true? What could be done to the draft to clean this up, and make it better?

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:17:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11442
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:17:29 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bstj-0005SO-L5
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:17:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2H3i4020970
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:17:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bstj-0005S9-HH
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:17:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11425
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:16:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bstg-0000fl-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:17:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bstf-0000fi-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:16:59 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bsth-0005Q8-0p; Sun, 13 Jul 2003 22:17:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bst0-0005Pn-FO
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:16:18 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11417
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:16:14 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bssx-0000fY-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:16:15 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bssw-0000fU-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:16:14 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-2.cisco.com with ESMTP; 13 Jul 2003 19:14:39 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2FhMK007991
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:15:43 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA04840
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:15:42 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:15:42 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132213520.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


IS the term "ownership" appropriate when discussing the advertisement of a
route or prefix? It doesn't appear to be, although it is used that way
within the draft, for instance section 4.5 and others. It appears that we
are concerned about attacks where a router claims to have reachability to a
given destination, not ownership of that destination, so the term is rather
loose, and we should work around it.

Thoughts?

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:25:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11589
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:25:29 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt1T-0005g8-QA
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:25:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2P3D1021822
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:25:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt1T-0005ft-Kh
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:25:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11572
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:24:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt1Q-0000iD-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:25:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt1P-0000iA-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:24:59 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt1R-0005dl-Dy; Sun, 13 Jul 2003 22:25:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt0n-0005dF-R1
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:24:21 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11564
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:24:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt0k-0000i4-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:24:18 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt0j-0000hw-01
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:24:17 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2NqMK008848
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:23:53 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA05210
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:23:51 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:23:51 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132219190.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Other Issue With the Threats Draft...
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Y'all:

I'd really like to get the threats draft moving again. I know I had sent
out a good number of comments earlier, and I've just sent out a bunch
again. I would really appreciate it if we could come to concensus on the
technical issues before us in this draft, and move on to editorial polish
issues, and move this out the door, so we can work on the requirements
document, and then on more specific protocol work.

Let's focus on the technical issues first, then lets get into polish and
editorial--we want this draft to be readable by the entire community,
rather than just a good technical document.

Thoughts?

:-)

Russ



__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:31:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11792
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:31:28 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt7G-0005y0-WC
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:31:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2V2X9022930
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:31:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt7G-0005xl-TF
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:31:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11758
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:30:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt7D-0000kp-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:30:59 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt7D-0000km-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:30:59 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt7F-0005wd-6K; Sun, 13 Jul 2003 22:31:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt6R-0005vq-EY
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:30:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11732
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:30:07 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt6O-0000kQ-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:30:08 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt6N-0000kC-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:30:07 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2TZAi006550
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:29:36 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA05384
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:29:35 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:29:34 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132228230.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Comments on the Abstract
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I think these comments were discarded as simple "grammar changes" earlier,
but I believe they change the technical thrust of the document, and should
be made:

   Routing protocols are subject to attacks that can harm individual
   users or the network operations as a whole. This document provides a
   description and a summary of generic threats that affects routing
   protocols in general. The work describes threats, including threat
   sources and capabilities, threat actions, and threat consequences as
   well as a breakdown of routing functions that might be separately
   attacked.

Replace with:

--
Routing protocols carry information about the topology of a network
which can be used to discover the best path to any given destination
within the network. The best path may be chosen based on its cost in
terms of bandwidth, delay, hop count, or other metric signifying the
length of the path, or it may be chosen based on some set of policies
designed by the network administrator. In either case, devices which
forward traffic (routers), using information and algorithms provided
by routing protocols, can make intelligent decisions when forwarding
traffic from one port to another.

Routing protocols, then are vulnerable to attacks against the
transportation of topology data, and attacks against the validity of
the topology data carried. This document describes the vulnerabilities
of routing protocols, including how they can be attacked in one of
these two areas, and how such attacks can be used to disrupt or
otherwise harm individual use of the network's resources, or force a
failure in the network denying the use of the network's resources in
general.

This work describes such attack methods in terms of threats, including
threat sources and capabilities, threat actions, and threat
consequences.
--

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:34:28 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11849
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:34:28 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btAA-00064o-Kh
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:34:02 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2Y2kZ023352
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:34:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btAA-00064Z-HW
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:34:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11841
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:33:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btA7-0000ly-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:33:59 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btA6-0000lv-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:33:58 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btA9-00063T-66; Sun, 13 Jul 2003 22:34:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19bt9O-00063C-7O
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:33:14 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11833
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:33:09 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt9K-0000lo-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:33:10 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bt9K-0000lk-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:33:10 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2WcMK010091
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:32:38 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA05512
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:32:38 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:32:37 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132230510.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Comments on Section 1, Introduction
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I would suggest we replace this section:

   denial of service, flooding attacks and others. The document does not
   consider threats that result from bad implementations that are
   related to specific routing.  The security requirements derived from
   this threat analysis are intended to be used as guidance to those who
   are designing routing protocols.

with:

While its well known that bad, incomplete, or poor implementations of
routing protocols may, in themselves, lead to routing problems or
failures, or may increase the risk of a network being attacked
successfully, these issues are not considered here. This document only
considers attacks against robust, well considered implementations of
routing protocols, as outlined in [OSPF], [IS-IS], [RIP], and [BGP].

(provide references for the above)

The security requirements derived from this analysis are intended to
be used as guidance to those who are designing and modifying routing
protocols. They may also be used by routing protocol implementors to
increase the robustness of their impmementations.

--

I'm not certain we reached any concensus on list.

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 22:38:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11931
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 22:38:28 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btE3-0006Uq-2F
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:38:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E2c3Ce024966
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 22:38:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btE2-0006Ub-U3
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 22:38:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11912
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 22:37:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btDz-0000n1-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:37:59 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btDy-0000my-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 22:37:58 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btE1-0006SV-1B; Sun, 13 Jul 2003 22:38:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btDQ-0006Kb-0k
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 22:37:24 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA11905
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:37:19 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btDM-0000mm-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:37:20 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btDL-0000mg-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 22:37:20 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-3.cisco.com with ESMTP; 13 Jul 2003 19:40:35 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6E2amAi007655
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:36:48 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA05692
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 22:36:47 -0400 (EDT)
Date: Sun, 13 Jul 2003 22:36:47 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
In-Reply-To: <Pine.WNT.4.55.0307132208080.1416@russpc>
Message-ID: <Pine.WNT.4.55.0307132236030.1416@russpc>
References: <Pine.WNT.4.55.0307132208080.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


BTW--my initial comment was to drop this section entirely, since I don't
really see why we should even discuss data and control planes as concepts
within routing protocols. In fact, I think there are other sections within
the docuemt that discuss this, and I think they should all be dropped.

Russ

On Sun, 13 Jul 2003, Russ White wrote:

>
> Sandy expressed some reservations about this section, stating that
> overloading the control plane and overloading the data plane are two
> seperate topics, and that routing protocol design could do little to help
> in either of them.
>
> Is there any concensus on this within the working group? I think we need
> some more discussion, probably?
>
> :-)
>
> Russ
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone
>
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 23:03:36 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12222
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 23:03:36 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btcN-00072P-4k
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:03:11 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E33Bq0027052
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:03:11 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btcM-00072F-Uz
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 23:03:10 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12213
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 23:03:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btcJ-0000sU-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:03:07 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btcI-0000sR-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:03:06 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btcD-000719-JH; Sun, 13 Jul 2003 23:03:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btc8-00070y-1G
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 23:02:56 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12210
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:02:51 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btc4-0000sO-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:02:52 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btc3-0000sG-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:02:51 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E32JMK014632
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:02:19 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id XAA06635
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:02:19 -0400 (EDT)
Date: Sun, 13 Jul 2003 23:02:18 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
In-Reply-To: <Pine.WNT.4.55.0307132200290.1416@russpc>
Message-ID: <Pine.WNT.4.55.0307132246220.1416@russpc>
References: <Pine.WNT.4.55.0307132200290.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Re: Threats Draft Issue 4: Section 3.1 Threat Sources
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


My original thought on this was to define these two seperately, but to call
them one thing within the draft. For instance, in my notes for section 3, I
had originally:

Replace:

   This section develops a model that can be used to identify the
   threats that can affect routing protocols in general. The model
   examines the possible threats that routing protocols can be exposed
   to from unauthorized entities.

with:

The model developed in this section can be used to identify threats to any
routing protocol. It examines attacks which can be launched against routing
from subverted entities within the routing system, and from entities
outside the routing system. Both of these types of entities are called
unauthorized entities.

--

I think this might be a good compromise text to work from.

:-)

Russ


On Sun, 13 Jul 2003, Russ White wrote:

>
> We don't seem to have gotten through a concensus on the threat sources
> portion of the threats draft, specifically in the seperation of
> unauthorized and masquerading threat sources. So, what I seem to have from
> the thread is:
>
> Sandy: We shouldn't consider masquerading and unauthorized as different
> Russ: Define the ideas, but combine them throughout the draft as one
>   problem
>
> Others? I'm not certain where we are on this topic.
>
> :-)
>
> Russ
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone
>
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 23:10:32 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12358
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 23:10:32 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btj5-0007Tk-5r
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:10:07 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E3A7LY028742
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:10:07 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btj4-0007TV-BB
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 23:10:06 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12342
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 23:10:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btj0-0000uj-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:10:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btiz-0000ug-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:10:01 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btj0-0007RR-2p; Sun, 13 Jul 2003 23:10:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btiB-0007Qk-VB
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 23:09:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12339
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:09:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bti8-0000uY-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:09:08 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19bti7-0000uP-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:09:07 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6E38ZAi011912
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:08:36 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id XAA06775
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:08:35 -0400 (EDT)
Date: Sun, 13 Jul 2003 23:08:35 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132304350.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] References in the Threats Draft
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


These should all be words, rather than numbers. This may seem a trivial
matter, but it greatly increases readability to include references as words
rather than numbers.

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 23:13:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12421
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 23:13:28 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btlt-0007dM-Ml
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:13:01 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E3D14O029338
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:13:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btlt-0007d7-CG
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 23:13:01 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12415
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 23:12:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btlr-0000w7-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:12:59 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btlq-0000w4-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:12:58 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btlr-0007b6-Nj; Sun, 13 Jul 2003 23:12:59 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btlM-0007am-BW
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 23:12:28 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12409
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:12:25 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btlK-0000vp-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:12:26 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btlJ-0000vO-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:12:25 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-3.cisco.com with ESMTP; 13 Jul 2003 20:15:42 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E3BsMK015632
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:11:54 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id XAA06846
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:11:53 -0400 (EDT)
Date: Sun, 13 Jul 2003 23:11:53 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132311010.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Section 3.1.1 Comments
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I think I originally asked this:

Replace this:

   neighbor. For example, in OSPF (that is, before the MD5 part was
   added), OSPF speaks to all routers on the local link that answer to
   the AllSPFRouters multicast address.  Furthermore, MANET protocols
   frequently speak over the broadcast link.

with:

For example, an OSPF router will form a peering relationship with any
attached device which appears to be running OSPF, unless MD5
authentication (or some other means) is used to prevent the peering
relationship from forming.

I'd pull the manet example, one is enough here, and reference the OSPF
MD5 draft.

--

Did we reach a concensus on this?

:-)

Russ



__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 13 23:15:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12473
	for <rpsec-archive@odin.ietf.org>; Sun, 13 Jul 2003 23:15:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btnq-0007iF-QQ
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:15:02 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6E3F23j029641
	for rpsec-archive@odin.ietf.org; Sun, 13 Jul 2003 23:15:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btnq-0007i0-IJ
	for rpsec-web-archive@optimus.ietf.org; Sun, 13 Jul 2003 23:15:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12463
	for <rpsec-web-archive@ietf.org>; Sun, 13 Jul 2003 23:14:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btno-0000x2-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:15:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btno-0000wz-00
	for rpsec-web-archive@ietf.org; Sun, 13 Jul 2003 23:15:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btno-0007fx-SF; Sun, 13 Jul 2003 23:15:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19btnI-0007fg-9S
	for rpsec@optimus.ietf.org; Sun, 13 Jul 2003 23:14:28 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA12460
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:14:25 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19btnG-0000ww-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:14:26 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19btnF-0000we-00
	for rpsec@ietf.org; Sun, 13 Jul 2003 23:14:25 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6E3DsMK015903
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:13:54 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-158.cisco.com [10.82.240.158])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id XAA06877
	for <rpsec@ietf.org>; Sun, 13 Jul 2003 23:13:53 -0400 (EDT)
Date: Sun, 13 Jul 2003 23:13:53 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307132313180.1416@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Question on Section 3.1.2.1
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


3.1.2.1 Threat Consequence Zone

   A threat consequence zone covers an area within which the network
   operations have been affected by the threat consequences.

I've never understood the consequences of a threat--do you mean the
area within which network operation has been affected by the
consequences of an attack? It seems to me what you're trying to say is
the zone where network operations would be impacted by an attack if a
given threat were exploited?

Was this question ever resolved?

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 14 16:49:40 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA25044
	for <rpsec-archive@odin.ietf.org>; Mon, 14 Jul 2003 16:49:40 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAG1-0001RD-6I
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 16:49:13 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6EKnDri005519
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 16:49:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAFz-0001Qw-ME
	for rpsec-web-archive@optimus.ietf.org; Mon, 14 Jul 2003 16:49:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA25002
	for <rpsec-web-archive@ietf.org>; Mon, 14 Jul 2003 16:49:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAFx-0007mD-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 16:49:09 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAFx-0007mA-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 16:49:09 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAFp-0001Pp-BC; Mon, 14 Jul 2003 16:49:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAD5-0001Ei-W4
	for rpsec@optimus.ietf.org; Mon, 14 Jul 2003 16:46:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA24757
	for <rpsec@ietf.org>; Mon, 14 Jul 2003 16:46:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAD4-0007iM-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 16:46:10 -0400
Received: from mesa.bbnplanet.com ([171.78.172.21])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAD3-0007iF-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 16:46:09 -0400
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6EKjUr06096;
	Mon, 14 Jul 2003 16:45:30 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Mon, 14 Jul 2003 16:45:30 -0400 (EDT)
From: Tony Tauber <tony.tauber@level3.com>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: Russ White <riw@cisco.com>
cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] References in the Threats Draft
In-Reply-To: <Pine.WNT.4.55.0307132304350.1416@russpc>
Message-ID: <Pine.GSO.4.56.0307141641200.6076@mesa.bbnplanet.com>
References: <Pine.WNT.4.55.0307132304350.1416@russpc>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Sun, 13 Jul 2003, Russ White wrote:

> These should all be words, rather than numbers. This may seem a
> trivial matter, but it greatly increases readability to include
> references as words rather than numbers.

Yes, yes, YES!  I always recommend this change on drafts I do a deep
review of.
This was part of my comments to some of the original revisions and
I actually put them into the first "individual" submitted draft on
behalf of the authors.  It seems like it didn't make it into the
second revision (WG submission).  Perhaps the problem was the XML
generator mechanism that was used for authoring that doesn't
understand non-numeric (ie. "mnemonic") references?

Tony

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 14 16:50:31 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA25127
	for <rpsec-archive@odin.ietf.org>; Mon, 14 Jul 2003 16:50:31 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAGq-0001Y6-OY
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 16:50:04 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6EKo45x005948
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 16:50:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAGq-0001Xr-Kk
	for rpsec-web-archive@optimus.ietf.org; Mon, 14 Jul 2003 16:50:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA25076
	for <rpsec-web-archive@ietf.org>; Mon, 14 Jul 2003 16:50:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAGo-0007nJ-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 16:50:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAGn-0007nG-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 16:50:01 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAGn-0001VD-1j; Mon, 14 Jul 2003 16:50:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cA7H-0000sx-Dj
	for rpsec@optimus.ietf.org; Mon, 14 Jul 2003 16:40:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA24271
	for <rpsec@ietf.org>; Mon, 14 Jul 2003 16:40:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cA7F-0007ap-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 16:40:09 -0400
Received: from mesa.bbnplanet.com ([171.78.172.21])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cA7E-0007aG-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 16:40:08 -0400
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6EKdSU06089;
	Mon, 14 Jul 2003 16:39:28 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Mon, 14 Jul 2003 16:39:28 -0400 (EDT)
From: Tony Tauber <tony.tauber@level3.com>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: Russ White <riw@cisco.com>
cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Comments on the Abstract
In-Reply-To: <Pine.WNT.4.55.0307132228230.1416@russpc>
Message-ID: <Pine.GSO.4.56.0307141630510.6076@mesa.bbnplanet.com>
References: <Pine.WNT.4.55.0307132228230.1416@russpc>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

I disagree, the proposed text is too wordy for an abstract.
I think the existing one suffices.  The new text can be added to the
Introduction if need be, though I don't think it's necessary in this
case.  The first paragraph is textbook material.  I'd hope anyone
who's involved in the IETF has already gotten the basics of what a
routing protocol does even if it's not their area of expertise.
I know you've had the textbook-writing hat on recently.  You may have
taken it off but still have "hat head". 8-)

Tony

On Sun, 13 Jul 2003, Russ White wrote:

> I think these comments were discarded as simple "grammar changes"
> earlier, but I believe they change the technical thrust of the
> document, and should be made:
>
>    Routing protocols are subject to attacks that can harm individual
>    users or the network operations as a whole. This document
>    provides a description and a summary of generic threats that
>    affects routing protocols in general. The work describes threats,
>    including threat sources and capabilities, threat actions, and
>    threat consequences as well as a breakdown of routing functions
>    that might be separately attacked.
>
> Replace with:
>
> --
> Routing protocols carry information about the topology of a network
> which can be used to discover the best path to any given destination
> within the network. The best path may be chosen based on its cost in
> terms of bandwidth, delay, hop count, or other metric signifying the
> length of the path, or it may be chosen based on some set of
> policies designed by the network administrator. In either case,
> devices which forward traffic (routers), using information and
> algorithms provided by routing protocols, can make intelligent
> decisions when forwarding traffic from one port to another.
>
> Routing protocols, then are vulnerable to attacks against the
> transportation of topology data, and attacks against the validity of
> the topology data carried. This document describes the
> vulnerabilities of routing protocols, including how they can be
> attacked in one of these two areas, and how such attacks can be used
> to disrupt or otherwise harm individual use of the network's
> resources, or force a failure in the network denying the use of the
> network's resources in general.
>
> This work describes such attack methods in terms of threats,
> including threat sources and capabilities, threat actions, and
> threat consequences.
> --
>
> Russ

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 14 17:03:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA25667
	for <rpsec-archive@odin.ietf.org>; Mon, 14 Jul 2003 17:03:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cATP-0002Ku-6Q
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:03:03 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6EL33Av008974
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:03:03 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cATP-0002Kf-30
	for rpsec-web-archive@optimus.ietf.org; Mon, 14 Jul 2003 17:03:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA25661
	for <rpsec-web-archive@ietf.org>; Mon, 14 Jul 2003 17:02:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cATM-00009b-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:03:01 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cATM-00009Y-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:03:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cATM-0002JU-WE; Mon, 14 Jul 2003 17:03:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cASu-0002J8-2U
	for rpsec@optimus.ietf.org; Mon, 14 Jul 2003 17:02:32 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA25655
	for <rpsec@ietf.org>; Mon, 14 Jul 2003 17:02:28 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cASr-00009P-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:02:30 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cASr-000090-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:02:29 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-3.cisco.com with ESMTP; 14 Jul 2003 14:05:55 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6EL1tMK020784;
	Mon, 14 Jul 2003 17:01:55 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-531.cisco.com [10.82.226.19])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id RAA26319;
	Mon, 14 Jul 2003 17:01:56 -0400 (EDT)
Date: Mon, 14 Jul 2003 17:01:56 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Tony Tauber <tony.tauber@level3.com>
cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Comments on the Abstract
In-Reply-To: <Pine.GSO.4.56.0307141630510.6076@mesa.bbnplanet.com>
Message-ID: <Pine.WNT.4.55.0307141655040.2676@russpc>
References: <Pine.WNT.4.55.0307132228230.1416@russpc>
 <Pine.GSO.4.56.0307141630510.6076@mesa.bbnplanet.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> I disagree, the proposed text is too wordy for an abstract. I think the
> existing one suffices.  The new text can be added to the Introduction if
> need be, though I don't think it's necessary in this case.  The first
> paragraph is textbook material.  I'd hope anyone who's involved in the
> IETF has already gotten the basics of what a routing protocol does even
> if it's not their area of expertise. I know you've had the
> textbook-writing hat on recently.  You may have taken it off but still
> have "hat head". 8-)

:-)

> >    Routing protocols are subject to attacks that can harm individual
> >    users or the network operations as a whole. This document

Could we at least change the first sentecnce, then, to something more
grammatical and thorough?

"Attacks against a routing protocol can harm individual or large numbers of
network users by impacting the network's ability to deliver packets to
their intended destination."

And, again, throughout: "The work" should be replaced with "This work."
It's not a third party thing--you're describing the draft from within the
draft, not another document from within the draft.

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 14 17:16:31 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26114
	for <rpsec-archive@odin.ietf.org>; Mon, 14 Jul 2003 17:16:31 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAg0-0003PJ-Mm
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:16:04 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6ELG4lM013093
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:16:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAg0-0003P6-G2
	for rpsec-web-archive@optimus.ietf.org; Mon, 14 Jul 2003 17:16:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26095
	for <rpsec-web-archive@ietf.org>; Mon, 14 Jul 2003 17:16:00 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAfy-0000FN-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:16:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAfx-0000FK-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:16:01 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAfy-0003Nv-Kn; Mon, 14 Jul 2003 17:16:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAfp-0003Nc-In
	for rpsec@optimus.ietf.org; Mon, 14 Jul 2003 17:15:53 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26087
	for <rpsec@ietf.org>; Mon, 14 Jul 2003 17:15:49 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAfn-0000FA-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:15:51 -0400
Received: from mesa.bbnplanet.com ([171.78.172.21])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAfm-0000Ex-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:15:50 -0400
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6ELF6v06106;
	Mon, 14 Jul 2003 17:15:06 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Mon, 14 Jul 2003 17:15:05 -0400 (EDT)
From: Tony Tauber <ttauber@genuity.net>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: Russ White <riw@cisco.com>
cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Comments on the Abstract
In-Reply-To: <Pine.WNT.4.55.0307141655040.2676@russpc>
Message-ID: <Pine.GSO.4.56.0307141706190.6076@mesa.bbnplanet.com>
References: <Pine.WNT.4.55.0307132228230.1416@russpc>
 <Pine.GSO.4.56.0307141630510.6076@mesa.bbnplanet.com>
 <Pine.WNT.4.55.0307141655040.2676@russpc>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Mon, 14 Jul 2003, Russ White wrote:

> > >    Routing protocols are subject to attacks that can harm
> > >    individual users or the network operations as a whole. This
> > >    document
>
> Could we at least change the first sentecnce, then, to something more
> grammatical and thorough?
>
> "Attacks against a routing protocol can harm individual or large
> numbers of network users by impacting the network's ability to
> deliver packets to their intended destination."

That's fine or just change "the network operations" to either
"the network's operations" or "network operations".

> And, again, throughout: "The work" should be replaced with "This
> work." It's not a third party thing--you're describing the draft
> from within the draft, not another document from within the draft.

Agreed.

Tony
----
ps. In your message about "Comments on Section1, Introduction" you
proposed text starting with:

"While its well known that bad, incomplete, or poor implementations of
routing protocols may, in themselves, lead to routing problems or..."

That "its" should be "it's".   I didn't bother then but we're on the
grammatical side so I bring it up.  I like that stuff. -T


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 14 17:18:29 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26233
	for <rpsec-archive@odin.ietf.org>; Mon, 14 Jul 2003 17:18:29 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAhu-0003VP-Kk
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:18:02 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6ELI20v013469
	for rpsec-archive@odin.ietf.org; Mon, 14 Jul 2003 17:18:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAhu-0003VA-Gt
	for rpsec-web-archive@optimus.ietf.org; Mon, 14 Jul 2003 17:18:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26177
	for <rpsec-web-archive@ietf.org>; Mon, 14 Jul 2003 17:17:58 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAhs-0000Gp-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:18:00 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAhr-0000Gm-00
	for rpsec-web-archive@ietf.org; Mon, 14 Jul 2003 17:17:59 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAht-0003TC-9h; Mon, 14 Jul 2003 17:18:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cAh3-0003Si-56
	for rpsec@optimus.ietf.org; Mon, 14 Jul 2003 17:17:09 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA26137
	for <rpsec@ietf.org>; Mon, 14 Jul 2003 17:17:05 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAh0-0000Fx-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:17:07 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cAgy-0000Fe-00
	for rpsec@ietf.org; Mon, 14 Jul 2003 17:17:05 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-2.cisco.com with ESMTP; 14 Jul 2003 14:15:42 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6ELGWAi007876;
	Mon, 14 Jul 2003 17:16:32 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-531.cisco.com [10.82.226.19])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id RAA27505;
	Mon, 14 Jul 2003 17:16:31 -0400 (EDT)
Date: Mon, 14 Jul 2003 17:16:31 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Tony Tauber <ttauber@genuity.net>
cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Comments on the Abstract
In-Reply-To: <Pine.GSO.4.56.0307141706190.6076@mesa.bbnplanet.com>
Message-ID: <Pine.WNT.4.55.0307141716020.2676@russpc>
References: <Pine.WNT.4.55.0307132228230.1416@russpc>
 <Pine.GSO.4.56.0307141630510.6076@mesa.bbnplanet.com>
 <Pine.WNT.4.55.0307141655040.2676@russpc> <Pine.GSO.4.56.0307141706190.6076@mesa.bbnplanet.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> > > >    Routing protocols are subject to attacks that can harm
> > > >    individual users or the network operations as a whole. This
> > > >    document
> >
> > Could we at least change the first sentecnce, then, to something more
> > grammatical and thorough?
> >
> > "Attacks against a routing protocol can harm individual or large
> > numbers of network users by impacting the network's ability to
> > deliver packets to their intended destination."
>
> That's fine or just change "the network operations" to either "the
> network's operations" or "network operations".

This would work as well....

> ps. In your message about "Comments on Section1, Introduction" you
> proposed text starting with:
>
> "While its well known that bad, incomplete, or poor implementations of
> routing protocols may, in themselves, lead to routing problems or..."
>
> That "its" should be "it's".   I didn't bother then but we're on the
> grammatical side so I bring it up.  I like that stuff. -T

Sure you don't want to edit some books? <hehe>

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Tue Jul 15 11:46:52 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA24825
	for <rpsec-archive@odin.ietf.org>; Tue, 15 Jul 2003 11:46:52 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cS0Y-0004O1-SI
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 11:46:26 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6FFkQ75016855
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 11:46:26 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cS0Y-0004Nm-Ft
	for rpsec-web-archive@optimus.ietf.org; Tue, 15 Jul 2003 11:46:26 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA24815
	for <rpsec-web-archive@ietf.org>; Tue, 15 Jul 2003 11:46:21 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cS0X-00036n-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 11:46:25 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cS0R-00036i-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 11:46:19 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cS08-0004N0-RC; Tue, 15 Jul 2003 11:46:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cRzh-0004JI-5p
	for rpsec@optimus.ietf.org; Tue, 15 Jul 2003 11:45:33 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA24774
	for <rpsec@ietf.org>; Tue, 15 Jul 2003 11:45:28 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cRzf-00036J-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 11:45:31 -0400
Received: from aragorn.bbn.com ([128.33.0.62])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cRzP-00033v-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 11:45:15 -0400
Received: from [81.160.154.206] (ssh.bbn.com [192.1.50.70])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h6FFhSD9014154;
	Tue, 15 Jul 2003 11:43:29 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@localhost
Message-Id: <p05200f05bb39d0fce655@[81.160.154.206]>
In-Reply-To: <Pine.WNT.4.55.0307132213520.1416@russpc>
References: <Pine.WNT.4.55.0307132213520.1416@russpc>
Date: Tue, 15 Jul 2003 11:43:39 -0400
To: Russ White <riw@cisco.com>
From: Stephen Kent <kent@bbn.com>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

At 22:15 -0400 7/13/03, Russ White wrote:
>IS the term "ownership" appropriate when discussing the advertisement of a
>route or prefix? It doesn't appear to be, although it is used that way
>within the draft, for instance section 4.5 and others. It appears that we
>are concerned about attacks where a router claims to have reachability to a
>given destination, not ownership of that destination, so the term is rather
>loose, and we should work around it.
>
>Thoughts?
>
>Russ
>

In BGP, the appropriate term seems to be "right to use" instead of 
"ownership" when referring to an organization that has address space 
(prefixes) allocated to it. With regard to a router advertisement (an 
UPDATE), the origin AS is asserting that it has been authorized by 
the "owner" to advertise the prefix in question.  Frankly, the 
alternative terms are awkward, so I suggest we stick with "owner" and 
put in a note about the preferred terms and our desire to stick with 
less verbose terminology.

Steve

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Tue Jul 15 12:00:39 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA25286
	for <rpsec-archive@odin.ietf.org>; Tue, 15 Jul 2003 12:00:39 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cSDt-00050p-Av
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 12:00:13 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6FG0D0s019263
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 12:00:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cSDt-00050c-6k
	for rpsec-web-archive@optimus.ietf.org; Tue, 15 Jul 2003 12:00:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA25268
	for <rpsec-web-archive@ietf.org>; Tue, 15 Jul 2003 12:00:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cSDr-0003E5-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 12:00:11 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cSDm-0003Dz-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 12:00:06 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cSDh-0004wr-EB; Tue, 15 Jul 2003 12:00:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cSDJ-0004w8-F6
	for rpsec@optimus.ietf.org; Tue, 15 Jul 2003 11:59:37 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA25234
	for <rpsec@ietf.org>; Tue, 15 Jul 2003 11:59:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cSDI-0003Dg-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 11:59:36 -0400
Received: from cumin.apnic.net ([202.12.29.59] helo=apnic.net)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cSD6-0003BS-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 11:59:25 -0400
Received: from zippy (dhcp19.apnic.net [202.12.29.148])
	by apnic.net (8.12.8/8.12) with ESMTP id h6FFwZPj020764;
	Wed, 16 Jul 2003 01:58:37 +1000
From: "Paul Wilson" <pwilson@apnic.net>
To: "'Stephen Kent'" <kent@bbn.com>, "'Russ White'" <riw@cisco.com>
Cc: "'Routing Protocols Security Working Group'" <rpsec@ietf.org>
Subject: RE: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Date: Wed, 16 Jul 2003 01:58:43 +1000
Organization: APNIC
Message-ID: <63B9746D4A92BF498D78584958F537E30A50B9@lotus.exchange>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4510
Importance: Normal
In-Reply-To: <p05200f05bb39d0fce655@[81.160.154.206]>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
X-AP-Spam-Status: No, hits=-106.2 required=7
X-AP-Spam-Score: -106.2 (notspam) BAYES_20,IN_REP_TO,QUOTED_EMAIL_TEXT,QUOTE_TWICE_1,USER_IN_WHITELIST
X-Scanned-By: MIMEDefang 2.15 (www dot roaringpenguin dot com slash mimedefang)
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

> -----Original Message-----
> From: rpsec-admin@ietf.org [mailto:rpsec-admin@ietf.org] On 
> Behalf Of Stephen Kent
> Sent: Wednesday, 16 July 2003 1:44 AM
> To: Russ White
> Cc: Routing Protocols Security Working Group
> Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
> 

> 
> In BGP, the appropriate term seems to be "right to use" instead of 
> "ownership" when referring to an organization that has address space 
> (prefixes) allocated to it. With regard to a router advertisement (an 
> UPDATE), the origin AS is asserting that it has been authorized by 
> the "owner" to advertise the prefix in question.  Frankly, the 
> alternative terms are awkward, so I suggest we stick with "owner" and 
> put in a note about the preferred terms and our desire to stick with 
> less verbose terminology.

In the RIR world, we tend to refer to a "registered holder" (or simply
"holder") of an address block or AS number, in preference to "owner".  

I would suggest that you consider "holder" as an alternative which is no
more awkward.

Paul Wilson
APNIC



_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Tue Jul 15 12:59:37 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA26892
	for <rpsec-archive@odin.ietf.org>; Tue, 15 Jul 2003 12:59:37 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cT8y-000857-TQ
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 12:59:13 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6FGxCFo031064
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 12:59:12 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cT8y-00084x-PL
	for rpsec-web-archive@optimus.ietf.org; Tue, 15 Jul 2003 12:59:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA26877
	for <rpsec-web-archive@ietf.org>; Tue, 15 Jul 2003 12:59:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cT8x-0003jy-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 12:59:11 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cT8r-0003jv-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 12:59:05 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cT8n-00082r-6L; Tue, 15 Jul 2003 12:59:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cT8a-00082d-Of
	for rpsec@optimus.ietf.org; Tue, 15 Jul 2003 12:58:48 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA26866
	for <rpsec@ietf.org>; Tue, 15 Jul 2003 12:58:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cT8Y-0003jk-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 12:58:46 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cT8M-0003j3-00
	for rpsec@ietf.org; Tue, 15 Jul 2003 12:58:34 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6FGsKMK017749;
	Tue, 15 Jul 2003 12:54:21 -0400 (EDT)
Received: from dhcp-64-102-60-168.cisco.com (dhcp-64-102-60-168.cisco.com [64.102.60.168])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id MAA21462;
	Tue, 15 Jul 2003 12:54:20 -0400 (EDT)
Date: Tue, 15 Jul 2003 12:54:41 -0400 (EDT)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Tony Tauber <tony.tauber@level3.com>
cc: Stephen Kent <kent@bbn.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
In-Reply-To: <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
Message-ID: <Pine.OSX.4.51.0307151253110.17935@dhcp-64-102-60-168.cisco.com>
References: <Pine.WNT.4.55.0307132213520.1416@russpc> <p05200f05bb39d0fce655@[81.160.154.206]>
 <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


So, we have:

-- use "own," with a definition to explain what we really mean
-- use 'authorized," which may entail some rewording/feel awkward?
-- use "holder,' which may also be awkward

Any other suggestions? Should we take a humm on one of these three?

:-)

Russ

On Tue, 15 Jul 2003, Tony Tauber wrote:

> On Tue, 15 Jul 2003, Stephen Kent wrote:
>
> > At 22:15 -0400 7/13/03, Russ White wrote:
> > >IS the term "ownership" appropriate when discussing the
> > >advertisement of a route or prefix? It doesn't appear to be,
> > >although it is used that way within the draft, for instance section
> > >4.5 and others. It appears that we are concerned about attacks
> > >where a router claims to have reachability to a given destination,
> > >not ownership of that destination, so the term is rather loose, and
> > >we should work around it.
> > >
> > >Thoughts?
> > >
> > >Russ
> > >
> >
> > In BGP, the appropriate term seems to be "right to use" instead of
> > "ownership" when referring to an organization that has address space
> > (prefixes) allocated to it. With regard to a router advertisement
> > (an UPDATE), the origin AS is asserting that it has been authorized
> > by the "owner" to advertise the prefix in question.  Frankly, the
> > alternative terms are awkward, so I suggest we stick with "owner"
> > and put in a note about the preferred terms and our desire to stick
> > with less verbose terminology.
> >
> > Steve
>
> How about "authorization" to advertise?
> Since we're trying to be generic, we ought to consider the case of a
> network under a single administration where the terminology of
> "ownership" makes no sense but the administrator of the network could
> be said to be authoritative.  For instance the administrator can
> decide that "this network belongs over here, that one belongs over
> there" and might also delegate some parts to sub-administrators.
>
> OK.  Egg on my face, I went back to the draft to try and propose
> alternate language and it looks like there's no mention of "ownership"
> or any form of the word "own" in the -01 draft from the IETF site.
> Looking back through my records, it looks like it was part of the
> section on overclaiming in the -00 rev but Abbie already updated it to
> read:
>
>    Over-claiming occurs when a subverted router advertises its control
>    of some network resources, while in reality it does not, or the
>    advertisement is not authorized.
>
> So, one down, X to go....
>
> Tony
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Tue Jul 15 13:05:33 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA27089
	for <rpsec-archive@odin.ietf.org>; Tue, 15 Jul 2003 13:05:33 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cTEi-0008ON-Of
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 13:05:08 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6FH58dw032253
	for rpsec-archive@odin.ietf.org; Tue, 15 Jul 2003 13:05:08 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cTEi-0008O8-L9
	for rpsec-web-archive@optimus.ietf.org; Tue, 15 Jul 2003 13:05:08 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA27078
	for <rpsec-web-archive@ietf.org>; Tue, 15 Jul 2003 13:05:02 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cTEg-0003oZ-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 13:05:06 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19cTEb-0003oW-00
	for rpsec-web-archive@ietf.org; Tue, 15 Jul 2003 13:05:01 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cTEb-0008Lb-Ei; Tue, 15 Jul 2003 13:05:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cSNd-00065W-0v
	for rpsec@optimus.ietf.org; Tue, 15 Jul 2003 12:10:17 -0400
Received: from mesa.bbnplanet.com (mesa.bbnplanet.com [171.78.172.21])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA25684
	for <rpsec@ietf.org>; Tue, 15 Jul 2003 12:10:11 -0400 (EDT)
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6FG2UJ06825;
	Tue, 15 Jul 2003 12:02:30 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Tue, 15 Jul 2003 12:02:30 -0400 (EDT)
From: Tony Tauber <tony.tauber@level3.com>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: Stephen Kent <kent@bbn.com>
cc: Russ White <riw@cisco.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
In-Reply-To: <p05200f05bb39d0fce655@[81.160.154.206]>
Message-ID: <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
References: <Pine.WNT.4.55.0307132213520.1416@russpc> <p05200f05bb39d0fce655@[81.160.154.206]>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Tue, 15 Jul 2003, Stephen Kent wrote:

> At 22:15 -0400 7/13/03, Russ White wrote:
> >IS the term "ownership" appropriate when discussing the
> >advertisement of a route or prefix? It doesn't appear to be,
> >although it is used that way within the draft, for instance section
> >4.5 and others. It appears that we are concerned about attacks
> >where a router claims to have reachability to a given destination,
> >not ownership of that destination, so the term is rather loose, and
> >we should work around it.
> >
> >Thoughts?
> >
> >Russ
> >
>
> In BGP, the appropriate term seems to be "right to use" instead of
> "ownership" when referring to an organization that has address space
> (prefixes) allocated to it. With regard to a router advertisement
> (an UPDATE), the origin AS is asserting that it has been authorized
> by the "owner" to advertise the prefix in question.  Frankly, the
> alternative terms are awkward, so I suggest we stick with "owner"
> and put in a note about the preferred terms and our desire to stick
> with less verbose terminology.
>
> Steve

How about "authorization" to advertise?
Since we're trying to be generic, we ought to consider the case of a
network under a single administration where the terminology of
"ownership" makes no sense but the administrator of the network could
be said to be authoritative.  For instance the administrator can
decide that "this network belongs over here, that one belongs over
there" and might also delegate some parts to sub-administrators.

OK.  Egg on my face, I went back to the draft to try and propose
alternate language and it looks like there's no mention of "ownership"
or any form of the word "own" in the -01 draft from the IETF site.
Looking back through my records, it looks like it was part of the
section on overclaiming in the -00 rev but Abbie already updated it to
read:

   Over-claiming occurs when a subverted router advertises its control
   of some network resources, while in reality it does not, or the
   advertisement is not authorized.

So, one down, X to go....

Tony

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Wed Jul 16 04:12:42 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA20355
	for <rpsec-archive@odin.ietf.org>; Wed, 16 Jul 2003 04:12:42 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19chOa-0001Ex-1w
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 04:12:16 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6G8CGLP004761
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 04:12:16 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19chOZ-0001Ei-RQ
	for rpsec-web-archive@optimus.ietf.org; Wed, 16 Jul 2003 04:12:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA20350
	for <rpsec-web-archive@ietf.org>; Wed, 16 Jul 2003 04:12:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19chOX-0004RM-00
	for rpsec-web-archive@ietf.org; Wed, 16 Jul 2003 04:12:13 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19chOR-0004RJ-00
	for rpsec-web-archive@ietf.org; Wed, 16 Jul 2003 04:12:07 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19chOK-0001Ck-NK; Wed, 16 Jul 2003 04:12:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19chNm-00019L-3n
	for rpsec@optimus.ietf.org; Wed, 16 Jul 2003 04:11:26 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA20307
	for <rpsec@ietf.org>; Wed, 16 Jul 2003 04:11:21 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19chNj-0004Qy-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 04:11:23 -0400
Received: from aragorn.bbn.com ([128.33.0.62])
	by ietf-mx with esmtp (Exim 4.12)
	id 19chNT-0004Q9-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 04:11:07 -0400
Received: from [81.160.154.206] (ssh.bbn.com [192.1.50.70])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h6G89iDD014234;
	Wed, 16 Jul 2003 04:09:49 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@localhost
Message-Id: <p05200f02bb3ab55d3774@[81.160.154.206]>
In-Reply-To: 
 <Pine.OSX.4.51.0307151253110.17935@dhcp-64-102-60-168.cisco.com>
References: <Pine.WNT.4.55.0307132213520.1416@russpc>
 <p05200f05bb39d0fce655@[81.160.154.206]>
 <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
 <Pine.OSX.4.51.0307151253110.17935@dhcp-64-102-60-168.cisco.com>
Date: Wed, 16 Jul 2003 03:55:54 -0400
To: Russ White <riw@cisco.com>
From: Stephen Kent <kent@bbn.com>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Cc: Tony Tauber <tony.tauber@level3.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

At 12:54 -0400 7/15/03, Russ White wrote:
>So, we have:
>
>-- use "own," with a definition to explain what we really mean
>-- use 'authorized," which may entail some rewording/feel awkward?
>-- use "holder,' which may also be awkward
>
>Any other suggestions? Should we take a humm on one of these three?
>
>:-)
>
>Russ
>

I can live with holder, aqlthough I prefer owner.

steve

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Wed Jul 16 07:46:37 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA26518
	for <rpsec-archive@odin.ietf.org>; Wed, 16 Jul 2003 07:46:37 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ckja-0005Ek-6e
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 07:46:10 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6GBkAnY020126
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 07:46:10 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ckja-0005EX-2a
	for rpsec-web-archive@optimus.ietf.org; Wed, 16 Jul 2003 07:46:10 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA26506
	for <rpsec-web-archive@ietf.org>; Wed, 16 Jul 2003 07:46:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ckjZ-0006I4-00
	for rpsec-web-archive@ietf.org; Wed, 16 Jul 2003 07:46:09 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19ckjT-0006I1-00
	for rpsec-web-archive@ietf.org; Wed, 16 Jul 2003 07:46:03 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ckjQ-0005DR-WC; Wed, 16 Jul 2003 07:46:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ckix-0005D0-8J
	for rpsec@optimus.ietf.org; Wed, 16 Jul 2003 07:45:31 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA26498
	for <rpsec@ietf.org>; Wed, 16 Jul 2003 07:45:28 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ckiw-0006Hn-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 07:45:30 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19ckil-0006Hb-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 07:45:19 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-3.cisco.com with ESMTP; 16 Jul 2003 04:49:07 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6GBifAi013059;
	Wed, 16 Jul 2003 07:44:42 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-435.cisco.com [10.82.241.179])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id HAA03696;
	Wed, 16 Jul 2003 07:44:41 -0400 (EDT)
Date: Wed, 16 Jul 2003 07:44:40 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Stephen Kent <kent@bbn.com>
cc: Tony Tauber <tony.tauber@level3.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
In-Reply-To: <p05200f02bb3ab55d3774@[81.160.154.206]>
Message-ID: <Pine.WNT.4.55.0307160744180.3480@russpc>
References: <Pine.WNT.4.55.0307132213520.1416@russpc> <p05200f05bb39d0fce655@[81.160.154.206]>
 <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
 <Pine.OSX.4.51.0307151253110.17935@dhcp-64-102-60-168.cisco.com>
 <p05200f02bb3ab55d3774@[81.160.154.206]>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


Thanks. I think I prefer owner with the approrpriate definitions in the
draft, as well.

:-)

Russ

On Wed, 16 Jul 2003, Stephen Kent wrote:

> At 12:54 -0400 7/15/03, Russ White wrote:
> >So, we have:
> >
> >-- use "own," with a definition to explain what we really mean
> >-- use 'authorized," which may entail some rewording/feel awkward?
> >-- use "holder,' which may also be awkward
> >
> >Any other suggestions? Should we take a humm on one of these three?
> >
> >:-)
> >
> >Russ
> >
>
> I can live with holder, aqlthough I prefer owner.
>
> steve
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Wed Jul 16 09:04:00 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA28655
	for <rpsec-archive@odin.ietf.org>; Wed, 16 Jul 2003 09:04:00 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19clwU-0001DD-Ks
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 09:03:34 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6GD3Y1g004659
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 09:03:34 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19clwU-0001D4-Fp
	for rpsec-web-archive@optimus.ietf.org; Wed, 16 Jul 2003 09:03:34 -0400
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA28632
	for <rpsec-web-archive@ietf.org>; Wed, 16 Jul 2003 09:03:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19clvx-00013a-My; Wed, 16 Jul 2003 09:03:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19clvA-00012k-9T
	for rpsec@optimus.ietf.org; Wed, 16 Jul 2003 09:02:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA28573
	for <rpsec@ietf.org>; Wed, 16 Jul 2003 09:02:07 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19clv8-0006sg-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 09:02:10 -0400
Received: from kanfw1.ottawa.alcatel.ca ([192.75.23.69] helo=kanmx1.ca.alcatel.com)
	by ietf-mx with smtp (Exim 4.12)
	id 19clux-0006sa-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 09:01:59 -0400
Received: (qmail 986 invoked from network); 16 Jul 2003 13:12:23 -0000
Received: from unknown (HELO CAOTTM00147) (138.120.62.35)
  by kanmx1.ca.alcatel.com with SMTP; 16 Jul 2003 13:12:23 -0000
Message-ID: <038201c34b9a$6ab68860$233e788a@CAOTTM00147>
From: "Emanuele Jones" <emanuele.jones@alcatel.com>
To: "Manral V-G19459" <vishwas@motorola.com>, <rpsec@ietf.org>
References: <653138C25D8AD6118292000347080A37055FBC5D@zin05exm02.corp.mot.com>
Subject: Re: [RPSEC] OSPF vulnerabilities draft
Date: Wed, 16 Jul 2003 09:01:38 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Vishwas,

thank you for you suggestion, I agree with you in the sense that this draft
may be usefull to the OSPF WG as well. I also believe that the RP-Sec WG is
supposed to leverage knowledge about threats and vulnerabilities of existing
routing protocols to better design the security requirement for future ones.
BGP was defeneately covered by this group, I thought this draft could cover
OSPF.
For example, I do not recall any discussion about ways to permanently
install malicious routes into an OSPF area without triggering *any*
reaction, or things of this matter, which are a major security flaw in
link-state protocols, where every peer knows the topology of its Area. These
kind of problems will still be present in the security of next generation
routing protocols unless we are aware of them today.

Regards,

Emanuele


----- Original Message -----
From: Manral V-G19459
To: 'Emanuele Jones' ; rpsec@ietf.org
Sent: Wednesday, July 16, 2003 2:32 AM
Subject: RE: [RPSEC] OSPF vulnerabilities draft


Hi Emanuele,

The draft might actually fit better in the OSPF working group, wouldn't it?

-Vishwas
-----Original Message-----
From: Emanuele Jones [mailto:emanuele.jones@alcatel.com]
Sent: Friday, July 11, 2003 23:21
To: rpsec@ietf.org
Subject: [RPSEC] OSPF vulnerabilities draft


Greetings,

I would like to introduce a new Internet Draft:
draft-jones-OSPF-vuln-00.txt. This draft is now available at the IETF
website.

I believe that even though the group has already moved to the developing of
a generic threat paper (draft-ietf-rpsec-routing-threats-01.txt), security
of IGP has not been extensively covered and discussed as much as EGP's
security was with BGP, SoBGP and SBGP. Thus, this paper may be a good
occasion to initiate some work on that topic. This memo systematically
dissects every message and every aspect of OSPF searching for
vulnerabilities that could lead to insider, outsider or DoS attacks against
the control and the data plane. The paper is more than just a literature
survey about OSPF security; aside from discovering new vulnerabilities that
came directly from the test bed, the draft highlights and describes a few
"misconceptions" about OSPF's security such as "fight back" and remote
attacker prevention.

The Internet Draft is available at:
http://www.ietf.org/internet-drafts/draft-jones-ospf-vuln-00.txt


Regards,

Emanuele

Emanuele Jones
Alcatel Canada - R&I - Security group
600 March Road - Kanata, ON, Canada K2K 2E6
Phone: +1 613 784 5977 Fax: +1 613 784 8944
Email: emanuele.jones@alcatel.com



_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Wed Jul 16 10:09:01 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA01663
	for <rpsec-archive@odin.ietf.org>; Wed, 16 Jul 2003 10:09:00 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cmxP-00058m-Ij
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 10:08:35 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6GE8Zwx019754
	for rpsec-archive@odin.ietf.org; Wed, 16 Jul 2003 10:08:35 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cmxP-00058X-FM
	for rpsec-web-archive@optimus.ietf.org; Wed, 16 Jul 2003 10:08:35 -0400
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA01603
	for <rpsec-web-archive@ietf.org>; Wed, 16 Jul 2003 10:08:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cmwq-00052h-FB; Wed, 16 Jul 2003 10:08:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19cmwc-0004zg-Gj
	for rpsec@optimus.ietf.org; Wed, 16 Jul 2003 10:07:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA01492
	for <rpsec@ietf.org>; Wed, 16 Jul 2003 10:07:41 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cmwa-0007Sv-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 10:07:44 -0400
Received: from dog.tcb.net ([64.78.150.133])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cmwP-0007Sj-00
	for rpsec@ietf.org; Wed, 16 Jul 2003 10:07:33 -0400
Received: from [81.160.194.110] (unknown [81.160.194.110])
	by dog.tcb.net (Postfix) with ESMTP id 20DB32029A
	for <rpsec@ietf.org>; Wed, 16 Jul 2003 08:08:34 -0600 (MDT)
User-Agent: Microsoft-Entourage/10.1.1.2418
Date: Wed, 16 Jul 2003 08:06:21 -0600
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
From: Danny McPherson <danny@tcb.net>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <BB3AB7FD.FE99%danny@tcb.net>
In-Reply-To: <p05200f02bb3ab55d3774@[81.160.154.206]>
Mime-version: 1.0
Content-type: text/plain; charset="US-ASCII"
Content-transfer-encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

On 7/16/03 1:55 AM, "Stephen Kent" <kent@bbn.com> wrote:
 
> I can live with holder, aqlthough I prefer owner.

me too...

-danny



_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 17 10:58:14 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA10411
	for <rpsec-archive@odin.ietf.org>; Thu, 17 Jul 2003 10:58:14 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dACb-0006AW-Bf
	for rpsec-archive@odin.ietf.org; Thu, 17 Jul 2003 10:57:49 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6HEvnmG023711
	for rpsec-archive@odin.ietf.org; Thu, 17 Jul 2003 10:57:49 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dACb-0006AM-7h
	for rpsec-web-archive@optimus.ietf.org; Thu, 17 Jul 2003 10:57:49 -0400
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA10396
	for <rpsec-web-archive@ietf.org>; Thu, 17 Jul 2003 10:57:43 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dABp-00065S-8l; Thu, 17 Jul 2003 10:57:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dABZ-00064o-SF
	for rpsec@optimus.ietf.org; Thu, 17 Jul 2003 10:56:46 -0400
Received: from mesa.bbnplanet.com (mesa.bbnplanet.com [171.78.172.21])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA10315
	for <rpsec@ietf.org>; Thu, 17 Jul 2003 10:56:39 -0400 (EDT)
Received: from localhost (ttauber@localhost)
	by mesa.bbnplanet.com (8.10.2+Sun/8.10.2) with ESMTP id h6HEn0t09224;
	Thu, 17 Jul 2003 10:49:00 -0400 (EDT)
X-Authentication-Warning: mesa.bbnplanet.com: ttauber owned process doing -bs
Date: Thu, 17 Jul 2003 10:49:00 -0400 (EDT)
From: Tony Tauber <tony.tauber@level3.com>
X-X-Sender: ttauber@mesa.bbnplanet.com
To: Emanuele Jones <emanuele.jones@alcatel.com>
cc: Manral V-G19459 <vishwas@motorola.com>, rpsec@ietf.org
Subject: Re: [RPSEC] OSPF vulnerabilities draftx
In-Reply-To: <038201c34b9a$6ab68860$233e788a@CAOTTM00147>
Message-ID: <Pine.GSO.4.56.0307171045040.6076@mesa.bbnplanet.com>
References: <653138C25D8AD6118292000347080A37055FBC5D@zin05exm02.corp.mot.com>
 <038201c34b9a$6ab68860$233e788a@CAOTTM00147>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Wed, 16 Jul 2003, Emanuele Jones wrote:
> > ----- Original Message -----
> > From: Manral V-G19459
> > To: 'Emanuele Jones' ; rpsec@ietf.org
> > Sent: Wednesday, July 16, 2003 2:32 AM
> > Subject: RE: [RPSEC] OSPF vulnerabilities draft
> >
> > Hi Emanuele,
> >
> > The draft might actually fit better in the OSPF working group,
> > wouldn't it?
> >
> > -Vishwas
>
> Vishwas,
>
> thank you for you suggestion, I agree with you in the sense that
> this draft may be usefull to the OSPF WG as well. I also believe
> that the RP-Sec WG is supposed to leverage knowledge about threats
> and vulnerabilities of existing routing protocols to better design
> the security requirement for future ones.  BGP was defeneately
> covered by this group, I thought this draft could cover OSPF.

Emanuele is correct, RPSEC is supposed to provide a focal point for
attention from both the routing community and security commuity.
Certainly, OSPF developers and WG should be interested as well in the
details though we probably want to avoid cross-posting.

Thanks,

Tony

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 17 13:16:45 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14213
	for <rpsec-archive@odin.ietf.org>; Thu, 17 Jul 2003 13:16:45 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dCMc-0005cs-Gd
	for rpsec-archive@odin.ietf.org; Thu, 17 Jul 2003 13:16:18 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6HHGI7u021622
	for rpsec-archive@odin.ietf.org; Thu, 17 Jul 2003 13:16:18 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dCMa-0005cf-Hc
	for rpsec-web-archive@optimus.ietf.org; Thu, 17 Jul 2003 13:16:17 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14191
	for <rpsec-web-archive@ietf.org>; Thu, 17 Jul 2003 13:16:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19dCMY-00001H-00
	for rpsec-web-archive@ietf.org; Thu, 17 Jul 2003 13:16:14 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19dCMS-000014-00
	for rpsec-web-archive@ietf.org; Thu, 17 Jul 2003 13:16:08 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dCML-0005aS-BP; Thu, 17 Jul 2003 13:16:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19dCLT-0005Zo-Aj
	for rpsec@optimus.ietf.org; Thu, 17 Jul 2003 13:15:07 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA14145
	for <rpsec@ietf.org>; Thu, 17 Jul 2003 13:15:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19dCLQ-00000U-00
	for rpsec@ietf.org; Thu, 17 Jul 2003 13:15:04 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19dCLD-0007n6-00
	for rpsec@ietf.org; Thu, 17 Jul 2003 13:14:52 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6HHBmMK016778;
	Thu, 17 Jul 2003 13:11:49 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-235.cisco.com [10.82.240.235])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id NAA06120;
	Thu, 17 Jul 2003 13:11:48 -0400 (EDT)
Date: Thu, 17 Jul 2003 13:11:48 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Tony Tauber <tony.tauber@level3.com>
cc: Emanuele Jones <emanuele.jones@alcatel.com>,
        Manral V-G19459 <vishwas@motorola.com>, rpsec@ietf.org
Subject: Re: [RPSEC] OSPF vulnerabilities draftx
In-Reply-To: <Pine.GSO.4.56.0307171045040.6076@mesa.bbnplanet.com>
Message-ID: <Pine.WNT.4.55.0307171310240.3288@russpc>
References: <653138C25D8AD6118292000347080A37055FBC5D@zin05exm02.corp.mot.com>
 <038201c34b9a$6ab68860$233e788a@CAOTTM00147> <Pine.GSO.4.56.0307171045040.6076@mesa.bbnplanet.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I see no reason not to bring this sort of work into the RPsec working
group. We are limited by our charter at the moment, but I think that as
long as we agree that the generic threats and requirements documents must
be done before we begin serious work on protocol specific threat models,
there's no reason not to hold this type of work within the working group,
letting them stay here until we can approach them more fully.

Thoughts?

:-)

Russ

On Thu, 17 Jul 2003, Tony Tauber wrote:

> On Wed, 16 Jul 2003, Emanuele Jones wrote:
> > > ----- Original Message -----
> > > From: Manral V-G19459
> > > To: 'Emanuele Jones' ; rpsec@ietf.org
> > > Sent: Wednesday, July 16, 2003 2:32 AM
> > > Subject: RE: [RPSEC] OSPF vulnerabilities draft
> > >
> > > Hi Emanuele,
> > >
> > > The draft might actually fit better in the OSPF working group,
> > > wouldn't it?
> > >
> > > -Vishwas
> >
> > Vishwas,
> >
> > thank you for you suggestion, I agree with you in the sense that
> > this draft may be usefull to the OSPF WG as well. I also believe
> > that the RP-Sec WG is supposed to leverage knowledge about threats
> > and vulnerabilities of existing routing protocols to better design
> > the security requirement for future ones.  BGP was defeneately
> > covered by this group, I thought this draft could cover OSPF.
>
> Emanuele is correct, RPSEC is supposed to provide a focal point for
> attention from both the routing community and security commuity.
> Certainly, OSPF developers and WG should be interested as well in the
> details though we probably want to avoid cross-posting.
>
> Thanks,
>
> Tony
>
> _______________________________________________
> RPSEC mailing list
> RPSEC@ietf.org
> https://www1.ietf.org/mailman/listinfo/rpsec
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 21 09:34:55 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26773
	for <rpsec-archive@odin.ietf.org>; Mon, 21 Jul 2003 09:34:55 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eao9-0004kI-2K
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 09:34:29 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6LDYTr7018241
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 09:34:29 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eao8-0004k8-Vt
	for rpsec-web-archive@optimus.ietf.org; Mon, 21 Jul 2003 09:34:29 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26746
	for <rpsec-web-archive@ietf.org>; Mon, 21 Jul 2003 09:34:24 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eao7-0002qk-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 09:34:27 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19eao1-0002qb-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 09:34:21 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eanh-0004dt-NK; Mon, 21 Jul 2003 09:34:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eanW-0004dW-J1
	for rpsec@optimus.ietf.org; Mon, 21 Jul 2003 09:33:50 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26733
	for <rpsec@ietf.org>; Mon, 21 Jul 2003 09:33:45 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eanU-0002q6-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 09:33:48 -0400
Received: from dns.nexthop.com ([65.247.36.216] helo=presque.nexthop.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19eanK-0002pf-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 09:33:38 -0400
Received: (from root@localhost)
	by presque.nexthop.com (8.12.9/8.11.1) id h6LDWS5D097050;
	Mon, 21 Jul 2003 09:32:28 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: from jhaas.nexthop.com (jhaas.nexthop.com [65.247.36.31])
	by presque.nexthop.com (8.12.9/8.12.8) with ESMTP id h6LDWOHr097043;
	Mon, 21 Jul 2003 09:32:24 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: (from jhaas@localhost)
	by jhaas.nexthop.com (8.11.3nb1/8.11.3) id h6LDWJO01188;
	Mon, 21 Jul 2003 09:32:19 -0400 (EDT)
Date: Mon, 21 Jul 2003 09:32:19 -0400
From: Jeffrey Haas <jhaas@nexthop.com>
To: Russ White <riw@cisco.com>
Cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030721093219.B1126@nexthop.com>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <Pine.WNT.4.55.0307132236030.1416@russpc>; from ruwhite@cisco.com on Sun, Jul 13, 2003 at 10:36:47PM -0400
X-Virus-Scanned: by AMaViS perl-11
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Sun, Jul 13, 2003 at 10:36:47PM -0400, Russ White wrote:
> BTW--my initial comment was to drop this section entirely, since I don't
> really see why we should even discuss data and control planes as concepts
> within routing protocols. In fact, I think there are other sections within
> the docuemt that discuss this, and I think they should all be dropped.

The only attack I can trivially think of has to do with DoS attacks
against the data plane that affect the control plane.  One example
is swamping the box with stuff that must be "process switched"
and thus potentially affecting the routing protocols.  The other
is saturating a link in such a fashion that control information can't
get through the link. 

A specific example of the latter is saturating your circuit to 99%
which causes your peering sessions to drop out.

> Russ

-- 
Jeff Haas 
NextHop Technologies

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 21 09:35:33 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26801
	for <rpsec-archive@odin.ietf.org>; Mon, 21 Jul 2003 09:35:33 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eaol-0004pq-PB
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 09:35:07 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6LDZ72J018580
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 09:35:07 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eaol-0004pb-L6
	for rpsec-web-archive@optimus.ietf.org; Mon, 21 Jul 2003 09:35:07 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26790
	for <rpsec-web-archive@ietf.org>; Mon, 21 Jul 2003 09:35:02 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eaoj-0002rL-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 09:35:05 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19eaoe-0002rI-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 09:35:00 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eaof-0004oP-DT; Mon, 21 Jul 2003 09:35:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19eaoa-0004o4-JI
	for rpsec@optimus.ietf.org; Mon, 21 Jul 2003 09:34:56 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA26771
	for <rpsec@ietf.org>; Mon, 21 Jul 2003 09:34:51 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eaoY-0002r2-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 09:34:54 -0400
Received: from dns.nexthop.com ([65.247.36.216] helo=presque.nexthop.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19eaoN-0002qH-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 09:34:44 -0400
Received: (from root@localhost)
	by presque.nexthop.com (8.12.9/8.11.1) id h6LDXtET097085;
	Mon, 21 Jul 2003 09:33:55 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: from jhaas.nexthop.com (jhaas.nexthop.com [65.247.36.31])
	by presque.nexthop.com (8.12.9/8.12.8) with ESMTP id h6LDXpHr097070;
	Mon, 21 Jul 2003 09:33:51 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: (from jhaas@localhost)
	by jhaas.nexthop.com (8.11.3nb1/8.11.3) id h6LDXkH01196;
	Mon, 21 Jul 2003 09:33:46 -0400 (EDT)
Date: Mon, 21 Jul 2003 09:33:46 -0400
From: Jeffrey Haas <jhaas@nexthop.com>
To: Russ White <riw@cisco.com>
Cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Message-ID: <20030721093346.C1126@nexthop.com>
References: <Pine.WNT.4.55.0307132213520.1416@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <Pine.WNT.4.55.0307132213520.1416@russpc>; from ruwhite@cisco.com on Sun, Jul 13, 2003 at 10:15:42PM -0400
X-Virus-Scanned: by AMaViS perl-11
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

The distinction is one of origination versus re-advertisement.
sobgp is meant to protect against that sort of attack in BGP. :-)

On Sun, Jul 13, 2003 at 10:15:42PM -0400, Russ White wrote:
> IS the term "ownership" appropriate when discussing the advertisement of a
> route or prefix? It doesn't appear to be, although it is used that way
> within the draft, for instance section 4.5 and others. It appears that we
> are concerned about attacks where a router claims to have reachability to a
> given destination, not ownership of that destination, so the term is rather
> loose, and we should work around it.
> 
> Thoughts?

-- 
Jeff Haas 
NextHop Technologies

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 21 10:40:48 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA29601
	for <rpsec-archive@odin.ietf.org>; Mon, 21 Jul 2003 10:40:48 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ebpu-0007e7-K6
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 10:40:23 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6LEeM9w029385
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 10:40:22 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ebpu-0007ds-DR
	for rpsec-web-archive@optimus.ietf.org; Mon, 21 Jul 2003 10:40:22 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA29570
	for <rpsec-web-archive@ietf.org>; Mon, 21 Jul 2003 10:40:16 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ebpr-0003PW-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 10:40:19 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19ebpm-0003PT-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 10:40:14 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ebpZ-0007bV-Ko; Mon, 21 Jul 2003 10:40:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ebol-0007ah-6I
	for rpsec@optimus.ietf.org; Mon, 21 Jul 2003 10:39:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA29528
	for <rpsec@ietf.org>; Mon, 21 Jul 2003 10:39:05 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eboi-0003OV-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 10:39:08 -0400
Received: from auds951.usa.alcatel.com ([143.209.238.80])
	by ietf-mx with esmtp (Exim 4.12)
	id 19eboX-0003Nu-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 10:38:57 -0400
Received: from alcatel.com (localhost [127.0.0.1])
	by auds951.usa.alcatel.com (8.12.8p1/8.12.8) with ESMTP id h6LEbSwA004185;
	Mon, 21 Jul 2003 09:37:28 -0500 (CDT)
Message-ID: <3F1BFAA6.FA3B0755@alcatel.com>
Date: Mon, 21 Jul 2003 09:37:26 -0500
From: Alex Audu <alex.audu@alcatel.com>
Reply-To: alex.audu@alcatel.com
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Stephen Kent <kent@bbn.com>
CC: Russ White <riw@cisco.com>, Tony Tauber <tony.tauber@level3.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
References: <Pine.WNT.4.55.0307132213520.1416@russpc>
	 <p05200f05bb39d0fce655@[81.160.154.206]>
	 <Pine.GSO.4.56.0307151149120.6076@mesa.bbnplanet.com>
	 <Pine.OSX.4.51.0307151253110.17935@dhcp-64-102-60-168.cisco.com> <p05200f02bb3ab55d3774@[81.160.154.206]>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

I'd go with "owner" too.

Cheers,
Alex.

Stephen Kent wrote:

> At 12:54 -0400 7/15/03, Russ White wrote:
> >So, we have:
> >
> >-- use "own," with a definition to explain what we really mean
> >-- use 'authorized," which may entail some rewording/feel awkward?
> >-- use "holder,' which may also be awkward
> >
> >Any other suggestions? Should we take a humm on one of these three?
> >
> >:-)
> >
> >Russ
> >
>
> I can live with holder, aqlthough I prefer owner.
>
> steve
>
> _______________________________________________
> RPSEC mailing list
> RPSEC@ietf.org
> https://www1.ietf.org/mailman/listinfo/rpsec


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 21 19:36:45 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA14928
	for <rpsec-archive@odin.ietf.org>; Mon, 21 Jul 2003 19:36:45 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ekCZ-0003PQ-UJ
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 19:36:20 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6LNaJcf013103
	for rpsec-archive@odin.ietf.org; Mon, 21 Jul 2003 19:36:19 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ekCZ-0003PG-Q6
	for rpsec-web-archive@optimus.ietf.org; Mon, 21 Jul 2003 19:36:19 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA14918
	for <rpsec-web-archive@ietf.org>; Mon, 21 Jul 2003 19:36:13 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ekCX-00075d-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 19:36:17 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19ekCR-00075a-00
	for rpsec-web-archive@ietf.org; Mon, 21 Jul 2003 19:36:11 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ekCI-0003Lc-9n; Mon, 21 Jul 2003 19:36:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19ekBn-0003L7-0U
	for rpsec@optimus.ietf.org; Mon, 21 Jul 2003 19:35:31 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA14910
	for <rpsec@ietf.org>; Mon, 21 Jul 2003 19:35:25 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ekBl-00075N-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 19:35:29 -0400
Received: from aragorn.bbn.com ([128.33.0.62])
	by ietf-mx with esmtp (Exim 4.12)
	id 19ekBV-00074c-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 19:35:13 -0400
Received: from [12.159.173.178] (ssh.bbn.com [192.1.50.70])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h6LNXxDB003691;
	Mon, 21 Jul 2003 19:34:01 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@localhost
Message-Id: <p05210601bb41ac8c8a2b@[128.89.89.40]>
In-Reply-To: <20030721093346.C1126@nexthop.com>
References: <Pine.WNT.4.55.0307132213520.1416@russpc>
 <20030721093346.C1126@nexthop.com>
Date: Mon, 21 Jul 2003 10:44:48 -0400
To: Jeffrey Haas <jhaas@nexthop.com>
From: Stephen Kent <kent@bbn.com>
Subject: Re: [RPSEC] Threats Draft Issue 7: Ownership as a Term
Cc: Russ White <riw@cisco.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

At 9:33 -0400 7/21/03, Jeffrey Haas wrote:
>The distinction is one of origination versus re-advertisement.
>sobgp is meant to protect against that sort of attack in BGP. :-)
>
>On Sun, Jul 13, 2003 at 10:15:42PM -0400, Russ White wrote:
>>  IS the term "ownership" appropriate when discussing the advertisement of a
>>  route or prefix? It doesn't appear to be, although it is used that way
>>  within the draft, for instance section 4.5 and others. It appears that we
>>  are concerned about attacks where a router claims to have reachability to a
>>  given destination, not ownership of that destination, so the term is rather
>>  loose, and we should work around it.
>>
>>  Thoughts?
>
>--
>Jeff Haas
>NextHop Technologies

Jeff,


the "ownership" vs. "right to use" vs. "holder" terminology deals 
exclusively with origin advertisements, not advertisement by later 
ASes.  Both soBGP and S-BGP addresses this problem, in analogous ways.

Steve

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Wed Jul 23 08:30:50 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA09576
	for <rpsec-archive@odin.ietf.org>; Wed, 23 Jul 2003 08:30:50 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fIlB-0006rW-En
	for rpsec-archive@odin.ietf.org; Wed, 23 Jul 2003 08:30:22 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6NCULtZ026376
	for rpsec-archive@odin.ietf.org; Wed, 23 Jul 2003 08:30:21 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fIlB-0006rL-AQ
	for rpsec-web-archive@optimus.ietf.org; Wed, 23 Jul 2003 08:30:21 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA09570
	for <rpsec-web-archive@ietf.org>; Wed, 23 Jul 2003 08:30:18 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fIl9-0004D8-00
	for rpsec-web-archive@ietf.org; Wed, 23 Jul 2003 08:30:19 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19fIl4-0004D1-00
	for rpsec-web-archive@ietf.org; Wed, 23 Jul 2003 08:30:14 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fIkq-0006qC-O5; Wed, 23 Jul 2003 08:30:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19egD5-00022U-TW
	for rpsec@optimus.ietf.org; Mon, 21 Jul 2003 15:20:35 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA08401
	for <rpsec@ietf.org>; Mon, 21 Jul 2003 15:20:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19egD4-0005eu-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 15:20:34 -0400
Received: from teldanex.hiit.fi ([212.68.5.99] helo=n97.nomadiclab.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19egCt-0005ec-00
	for rpsec@ietf.org; Mon, 21 Jul 2003 15:20:24 -0400
Received: from nomadiclab.com (polle.local.nikander.com [192.168.0.193])
	by n97.nomadiclab.com (Postfix) with ESMTP
	id 8A8B11C; Mon, 21 Jul 2003 22:29:27 +0300 (EEST)
Message-ID: <3F1C3CD4.4090603@nomadiclab.com>
Date: Mon, 21 Jul 2003 22:19:48 +0300
From: Pekka Nikander <pekka.nikander@nomadiclab.com>
Reply-To: Pekka Nikander <pekka.nikander@nomadiclab.com>
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.3) Gecko/20030312
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: saag@mit.edu, ipsec@lists.tislabs.com, rpsec@ietf.org
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Subject: [RPSEC] New mailing list to discuss IP layer signalling security
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

As agreed at SAAG at IETF-57, Vienna, we now have
a mailing list to discuss IP layer signalling security.
The aim is to discuss the problem, and find out whether
there would be enough of interest to look at the more
generic problem to warrant an IETF working group.

The ML is kindly hosted by VPNC (thanks, Paul).  To
subscribe, either access the web page at

   http://www.vpnc.org/ietf-ipsigsec/index.html

or simply send a message to <ietf-ipsigsec-request@vpnc.org>
with the single word subscribe in the body of the message.

To give people time to subscribe to the list, it is not
yet possible to post to the list.  Once posting becomes
possible I will send a separate note to the *list* (not here).

The mailing list is chartered as follows.  If you think
that this chartering is not what was earlier discussed at
the saag ML or at the meeting, please send e-mail to me.

------------------------------

Initial ML Charter:

The ietf-ipsigsec mailing list is for discussing standizing
protocols or protocol components for securing IP layer
signalling protocols, such as IPv6 Neighbor Discovery and
Autoconfiguration, Mobile IP, Mobile IP optimization protocols,
and perhaps some routing protocols. This mailing list may
turn into an IETF Working Group.

As a background, experience has shown that the IPsec
Authentication Header (AH), as it is currently standardized,
does not cover the requirements. Hence, for example, the
Mobile IPv6 Route Optimization and Secure IPv6 Neighbor
Discovery (SEND) both use more-or-less ad hoc, protocol
specific mechanisms to reach their security goals. One
purpose of this mailing list is to see if something can
be learned from these experiences.

The topics, to be discussed on the mailing list, are the
following:

     * Address the need for generic protocol components that
       could be used to secure current and future IP layer
       (internetworking layer) signalling protocols. Examples
       of components to consider include Return Routability (RR)
       and Cryptographically Generated Addresses (CGA).

     * Progress towards a security model that would cover all
       or most IP layer signalling protocol security requirements.
       The focus is on situations where one cannot rely on
       existing or supposed security infrastructures.

     * Understand how the proposed separation of the identifier
       and locator roles of IP addresses may affect the security
       requirements in the IP layer signalling scope.

     * Based on the topics above, consider the applicability of
       the IPsec AH protocol. That is, it is allowed to state that
       there seems to be no use of AH within this space, or that AH
       seems to be a perfect match to the needs, as long as such
       statements are well founded and based on discussion on the
       items above. However, it is strictly out of scope to state
       opinions on AH without basing those opinions on clearly
       argumented technical discussion, or to discuss the applicability
       of AH for any other purpose but IP layer signalling security.


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 24 10:05:43 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA07137
	for <rpsec-archive@odin.ietf.org>; Thu, 24 Jul 2003 10:05:43 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fgib-0006f7-Fm
	for rpsec-archive@odin.ietf.org; Thu, 24 Jul 2003 10:05:18 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6OE5HoT025608
	for rpsec-archive@odin.ietf.org; Thu, 24 Jul 2003 10:05:17 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fgib-0006ex-CZ
	for rpsec-web-archive@optimus.ietf.org; Thu, 24 Jul 2003 10:05:17 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA07020
	for <rpsec-web-archive@ietf.org>; Thu, 24 Jul 2003 10:05:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fgiY-0006FW-00
	for rpsec-web-archive@ietf.org; Thu, 24 Jul 2003 10:05:14 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19fgiT-0006FN-00
	for rpsec-web-archive@ietf.org; Thu, 24 Jul 2003 10:05:09 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fghN-0006Sy-9q; Thu, 24 Jul 2003 10:04:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fgh1-0006S3-Sp
	for rpsec@optimus.ietf.org; Thu, 24 Jul 2003 10:03:39 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA06822
	for <rpsec@ietf.org>; Thu, 24 Jul 2003 10:03:34 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fggz-0006EX-00
	for rpsec@ietf.org; Thu, 24 Jul 2003 10:03:37 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fggo-0006EB-00
	for rpsec@ietf.org; Thu, 24 Jul 2003 10:03:26 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP
	id 4D74B33D32; Thu, 24 Jul 2003 15:55:04 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP
	id EED573F44C; Thu, 24 Jul 2003 16:17:29 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003072415550309687
 ; Thu, 24 Jul 2003 15:55:03 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP
	id 4A7733F44C; Thu, 24 Jul 2003 16:17:29 +0200 (CEST)
Received: from jjp by localhost with local id 19fgYf-0005Q8-00; Thu, 24 Jul 2003 15:55:01 +0200
Date: Thu, 24 Jul 2003 15:55:01 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: Jeffrey Haas <jhaas@nexthop.com>
Cc: Russ White <riw@cisco.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030724135501.GC17957@ivan.int-evry.fr>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20030721093219.B1126@nexthop.com>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Mon, Jul 21, 2003 at 09:32:19AM -0400, Jeffrey Haas wrote:
> 
> The only attack I can trivially think of has to do with DoS attacks
> against the data plane that affect the control plane.  One example
> is swamping the box with stuff that must be "process switched"
> and thus potentially affecting the routing protocols.  The other
> is saturating a link in such a fashion that control information can't
> get through the link. 
> 
> A specific example of the latter is saturating your circuit to 99%
> which causes your peering sessions to drop out.

Or to slow down in such a way that routing protocol convergence will
let enough time for the attacker to enjoy current / intermediate routes
state.

Anyway, I think we should agree on the fact that this has little to do
with the routing protocol. It would fit better in a document dealing
with security of routing devices operations.

-- 
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 24 10:25:16 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA08780
	for <rpsec-archive@odin.ietf.org>; Thu, 24 Jul 2003 10:25:16 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fh1X-0008LX-MG
	for rpsec-archive@odin.ietf.org; Thu, 24 Jul 2003 10:24:51 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6OEOpOm032084
	for rpsec-archive@odin.ietf.org; Thu, 24 Jul 2003 10:24:51 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fh1X-0008LP-7b
	for rpsec-web-archive@optimus.ietf.org; Thu, 24 Jul 2003 10:24:51 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA08751
	for <rpsec-web-archive@ietf.org>; Thu, 24 Jul 2003 10:24:45 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fh1U-0006P1-00
	for rpsec-web-archive@ietf.org; Thu, 24 Jul 2003 10:24:48 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19fh1P-0006Oy-00
	for rpsec-web-archive@ietf.org; Thu, 24 Jul 2003 10:24:43 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fh0j-0008Hj-Ac; Thu, 24 Jul 2003 10:24:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19fh0d-0008HY-TG
	for rpsec@optimus.ietf.org; Thu, 24 Jul 2003 10:23:55 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA08734
	for <rpsec@ietf.org>; Thu, 24 Jul 2003 10:23:50 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fh0b-0006Od-00
	for rpsec@ietf.org; Thu, 24 Jul 2003 10:23:53 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fh0Q-0006OR-00
	for rpsec@ietf.org; Thu, 24 Jul 2003 10:23:42 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP
	id 3F0DD33B04; Thu, 24 Jul 2003 16:23:07 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP
	id 346043F445; Thu, 24 Jul 2003 16:45:33 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003072416230606498
 ; Thu, 24 Jul 2003 16:23:06 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP
	id 041CC3F445; Thu, 24 Jul 2003 16:45:33 +0200 (CEST)
Received: from jjp by localhost with local id 19fgzo-0005S7-00; Thu, 24 Jul 2003 16:23:04 +0200
Date: Thu, 24 Jul 2003 16:23:04 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: Russ White <riw@cisco.com>
Cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Threats Draft Issue 6: Consistent Use of Blackhole
Message-ID: <20030724142304.GD17957@ivan.int-evry.fr>
References: <Pine.WNT.4.55.0307132211230.1416@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.WNT.4.55.0307132211230.1416@russpc>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Sun, Jul 13, 2003 at 10:13:18PM -0400, Russ White wrote:
> 
> Sandy brought up, some time back, that the term blackhole didn't appear to
> be used consistently throughout the threats draft. Does the WG feel this is
> true? What could be done to the draft to clean this up, and make it better?

Looks like blackhole is in effect used unconsistently throughout the
draft, though it appears only twice in current version :). I think that
it's worth considering that a blackhole is the damage part of a threat
consequence as stated in section 3.1.2.

The other occurence is (same section):
   It
   might be possible to design a security solution that protected
   against an attack that eavesdropped on one destination's traffic
   without protecting against an attack that overwhelmed a router.  Or
   that prevented a starvation attack against one host, but not against
   a net wide blackhole. 

Is a starvation attack against a blackhole possible ? It would be
attacking a damage, wouldn't it  ? Correct rephrasing may be:

	  Or
   that prevented a starvation attack against one host, but not against
   a net wide resources.

Starvation of net wide resources may, as a consequence, result in a kind of net wide blackhole.

This was my 2cts

-- 
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Fri Jul 25 14:52:43 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15225
	for <rpsec-archive@odin.ietf.org>; Fri, 25 Jul 2003 14:52:42 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19g7ft-00046c-5e
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 14:52:18 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6PIqHKe015778
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 14:52:17 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19g7ft-00046P-1Q
	for rpsec-web-archive@optimus.ietf.org; Fri, 25 Jul 2003 14:52:17 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15217
	for <rpsec-web-archive@ietf.org>; Fri, 25 Jul 2003 14:52:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19g7fq-0002ek-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 14:52:14 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19g7fp-0002eg-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 14:52:13 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19g7fc-00044G-Vy; Fri, 25 Jul 2003 14:52:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19g7fN-000443-7q
	for rpsec@optimus.ietf.org; Fri, 25 Jul 2003 14:51:45 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15203
	for <rpsec@ietf.org>; Fri, 25 Jul 2003 14:51:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19g7fK-0002eP-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 14:51:42 -0400
Received: from auds951.usa.alcatel.com ([143.209.238.80])
	by ietf-mx with esmtp (Exim 4.12)
	id 19g7fJ-0002eH-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 14:51:41 -0400
Received: from alcatel.com (localhost [127.0.0.1])
	by auds951.usa.alcatel.com (8.12.8p1/8.12.8) with ESMTP id h6PIomwA005794;
	Fri, 25 Jul 2003 13:50:49 -0500 (CDT)
Message-ID: <3F217C07.15160537@alcatel.com>
Date: Fri, 25 Jul 2003 13:50:47 -0500
From: Alex Audu <alex.audu@alcatel.com>
Reply-To: alex.audu@alcatel.com
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
CC: Jeffrey Haas <jhaas@nexthop.com>, Russ White <riw@cisco.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

 The fact that you can indirectly attack the control by attacking the data
plane
doesn't lessen the ramification that  it could be a threat to routing
functions. I think
this should be mentioned in the threat document.

Designers should be able to refer to the threat document to help them
develop
more threat-safe routing devices.

One benefit of separating Control and Data planes is that it may afford the
control plane somewhat of an isolated castle that could be more easily
shielded from outside attacks. One could do things like having separate
streams for data and control between control and forwarding planes. Also,
rate limiting could be used to improve
safety.

Regards,
Alex.


Jean-Jacques Puig wrote:

> On Mon, Jul 21, 2003 at 09:32:19AM -0400, Jeffrey Haas wrote:
> >
> > The only attack I can trivially think of has to do with DoS attacks
> > against the data plane that affect the control plane.  One example
> > is swamping the box with stuff that must be "process switched"
> > and thus potentially affecting the routing protocols.  The other
> > is saturating a link in such a fashion that control information can't
> > get through the link.
> >
> > A specific example of the latter is saturating your circuit to 99%
> > which causes your peering sessions to drop out.
>
> Or to slow down in such a way that routing protocol convergence will
> let enough time for the attacker to enjoy current / intermediate routes
> state.
>
> Anyway, I think we should agree on the fact that this has little to do
> with the routing protocol. It would fit better in a document dealing
> with security of routing devices operations.
>
> --
> Jean-Jacques Puig
>
> [homepage] http://www-lor.int-evry.fr/~puig/
>
> _______________________________________________
> RPSEC mailing list
> RPSEC@ietf.org
> https://www1.ietf.org/mailman/listinfo/rpsec


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Fri Jul 25 22:00:36 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA05996
	for <rpsec-archive@odin.ietf.org>; Fri, 25 Jul 2003 22:00:36 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gELy-0006J8-Vm
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 22:00:11 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6Q20AGR024245
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 22:00:10 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gELy-0006Iy-RY
	for rpsec-web-archive@optimus.ietf.org; Fri, 25 Jul 2003 22:00:10 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA05992
	for <rpsec-web-archive@ietf.org>; Fri, 25 Jul 2003 22:00:05 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gELv-0000Zb-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 22:00:07 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gELv-0000ZY-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 22:00:07 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gELp-0006Hf-EP; Fri, 25 Jul 2003 22:00:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gELg-0006H8-8r
	for rpsec@optimus.ietf.org; Fri, 25 Jul 2003 21:59:52 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA05970
	for <rpsec@ietf.org>; Fri, 25 Jul 2003 21:59:46 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gELd-0000ZA-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 21:59:49 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gELc-0000Yl-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 21:59:48 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6Q1xCAi018964;
	Fri, 25 Jul 2003 21:59:12 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-656.cisco.com [10.82.242.144])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id VAA04723;
	Fri, 25 Jul 2003 21:59:11 -0400 (EDT)
Date: Fri, 25 Jul 2003 21:59:10 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Alex Audu <alex.audu@alcatel.com>
cc: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>,
        Jeffrey Haas <jhaas@nexthop.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <3F217C07.15160537@alcatel.com>
Message-ID: <Pine.WNT.4.55.0307252154320.908@russpc>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
 <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
 <3F217C07.15160537@alcatel.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> The fact that you can indirectly attack the control by attacking the data
> plane doesn't lessen the ramification that it could be a threat to
> routing functions. I think this should be mentioned in the threat
> document.
>
> Designers should be able to refer to the threat document to help them
> develop more threat-safe routing devices.

I tend to diagree--this is at a lower layer, and we shouldn'tneed to
mention every possible lower layer attack. For instance, gaining access to
the console can also get you into a position to attack the routing system,
but I'm not certain we should include that in the threat analysis.

> One benefit of separating Control and Data planes is that it may afford
> the control plane somewhat of an isolated castle that could be more
> easily shielded from outside attacks. One could do things like having
> separate streams for data and control between control and forwarding
> planes. Also, rate limiting could be used to improve safety.

I don't think the conclusion that separating the data plane from the
control plane is much help in preventing port flooding attacks. The router
still has to receive packets in order to run a routing protocol; seperating
the data plane from the control plane isn't going to stop an attacker from
attacking thosse ports open for a router to receive packets.

Seperating the data and control plane is a good characteristic in many
situations, but as a method to provide security, I'm not certain it
actually helps anything (?).

:-)

Russ

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Fri Jul 25 22:42:30 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA06752
	for <rpsec-archive@odin.ietf.org>; Fri, 25 Jul 2003 22:42:30 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gF0Y-0007wO-1T
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 22:42:06 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6Q2g6IK030518
	for rpsec-archive@odin.ietf.org; Fri, 25 Jul 2003 22:42:06 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gF0X-0007w9-Um
	for rpsec-web-archive@optimus.ietf.org; Fri, 25 Jul 2003 22:42:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA06739
	for <rpsec-web-archive@ietf.org>; Fri, 25 Jul 2003 22:41:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gF0U-0000nN-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 22:42:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gF0U-0000nK-00
	for rpsec-web-archive@ietf.org; Fri, 25 Jul 2003 22:42:02 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gF0T-0007v0-PJ; Fri, 25 Jul 2003 22:42:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gF03-0007uM-0X
	for rpsec@optimus.ietf.org; Fri, 25 Jul 2003 22:41:35 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA06721
	for <rpsec@ietf.org>; Fri, 25 Jul 2003 22:41:28 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gEzz-0000mk-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 22:41:31 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gEzz-0000lt-00
	for rpsec@ietf.org; Fri, 25 Jul 2003 22:41:31 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-3.cisco.com with ESMTP; 25 Jul 2003 19:41:03 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6Q2exAi025863
	for <rpsec@ietf.org>; Fri, 25 Jul 2003 22:40:59 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn2-656.cisco.com [10.82.242.144])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id WAA06544
	for <rpsec@ietf.org>; Fri, 25 Jul 2003 22:40:58 -0400 (EDT)
Date: Fri, 25 Jul 2003 22:40:57 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Message-ID: <Pine.WNT.4.55.0307252202210.908@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [RPSEC] Threats Draft Issues: Where we Stand?
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Y'all:

We've had some discussion over some of the issues on the threats draft I
had recorded from various places; below is a summary of what I have so far.
We need to get this cleaned up and finished up, so we can move on to other
work in the near future.

In other words: Please read the drafts and the issues, and comment on them,
so we can make certain we have some semblance of agreement on each of the
issues. I think Abbi has promised a revision in two weeks, if we can come
to agreement on each of these issues.

Is there anyone on list that thinks the draft, in general, is "not right,"
in some way? Are we all okay with with the format, etc, or the draft? I
remember there was some discussion on this, but I'm not certain any sort of
concensus was ever reached on this topic.

:-)

Russ

--

Current Issues and Status:

Issue 1: Use neighbors throughout to describe two adjacent routers running
the same protocol, etc. I think

Status: I think we have concensus on this.

Issue 2: Section 4.1, Is deliberate exposure a threat to a routing system?

Status: We have one comment that it is a threat, and no other comments that
I've seen. Do I take it that deliberate exposure is a threat to routing?

Issue 3: Issue 3: Section 4.5, Is underclaiming a threat to routing
systems?

Status: I seem to remember Sandy and some others arguing against
underclaiming being a threat, while I and others argue for it being a
threat. The reasoning on one side appears to be that you can't force a
router to advertise anything (?), while on the other side the claim is that
this doesn't matter, forcinf information can still cause misrouting to
occur, and thus it's a threat. It seems we need some closure on this one.

Issue 4: Section 3.1, Splitting masquerading threats from unauthorized
threats.

Status: I don't think I've seen any concensus here (?). I take the silence
on the issue to mean that the compromise text I proposed is okay with
everyone, defining them seperately, but using the same term for the two
throughout.

Issue 5: Is the term blackhole used consistently throughout?

Status: The term only appears to used twice in the draft as it is right
now, and it appears to be used consistently. I take this as a concensus on
this item.

Issue 6: Section 4.7 Is overload a legitimate attack against a routing
protocol?

Status: Thus far, we have Jeff, Jean-Jacques, and I arguing against it
being a threat, and Alex A arguing it is a threat. What's the concensus on
this one? I'm inclined to all it not a threat based on the current
arguments.

Issue 7: Ownership as a term.... Is ownership the right term to use?

Status: I think we've reached concensus on this one, with "owner" being the
acceptable term, as long as it is defined at the beginnig of the doc.

Issue 8: In the abstract, there's an awkwardly worded sentence:

Status: I take the following as a concensus change:

> That's fine or just change "the network operations" to either "the
> network's operations" or "network operations".

This would work as well....

> ps. In your message about "Comments on Section1, Introduction" you
> proposed text starting with:
>
> "While its well known that bad, incomplete, or poor implementations of
> routing protocols may, in themselves, lead to routing problems or..."
>
> That "its" should be "it's".   I didn't bother then but we're on the
> grammatical side so I bring it up.  I like that stuff. -T

Issue 9: Use words rather than numbers for references.

Status: I assume we have concensus on this.

Issue 10: Section 3.1.2.1 Threat Consequence Zone

Status: I've seen no discussion on this issue--does everyone else
understand this section of the draft completely?






__________________________________
riw@cisco.com CCIE <>< Grace Alone




_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sat Jul 26 00:02:36 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA09732
	for <rpsec-archive@odin.ietf.org>; Sat, 26 Jul 2003 00:02:36 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gGG2-0002re-Hf
	for rpsec-archive@odin.ietf.org; Sat, 26 Jul 2003 00:02:10 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6Q428bK011004
	for rpsec-archive@odin.ietf.org; Sat, 26 Jul 2003 00:02:08 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gGFz-0002rP-Sd
	for rpsec-web-archive@optimus.ietf.org; Sat, 26 Jul 2003 00:02:08 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA09692
	for <rpsec-web-archive@ietf.org>; Sat, 26 Jul 2003 00:02:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gGFx-00029N-00
	for rpsec-web-archive@ietf.org; Sat, 26 Jul 2003 00:02:05 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gGFw-00029K-00
	for rpsec-web-archive@ietf.org; Sat, 26 Jul 2003 00:02:04 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gGFu-0002qH-9c; Sat, 26 Jul 2003 00:02:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gGEz-0002mD-Ix
	for rpsec@optimus.ietf.org; Sat, 26 Jul 2003 00:01:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA09611
	for <rpsec@ietf.org>; Sat, 26 Jul 2003 00:00:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gGEx-00027u-00
	for rpsec@ietf.org; Sat, 26 Jul 2003 00:01:03 -0400
Received: from kc-msxproto1.kc.umkc.edu ([134.193.143.167])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gGEw-00027r-00
	for rpsec@ietf.org; Sat, 26 Jul 2003 00:01:02 -0400
Received: from sarah ([65.27.6.64]) by kc-msxproto1.kc.umkc.edu with Microsoft SMTPSVC(6.0.3790.0);
	 Fri, 25 Jul 2003 23:00:56 -0500
Reply-To: <dhuang@conrel.sice.umkc.edu>
From: "Dijiang Huang" <dhuang@conrel.sice.umkc.edu>
To: "Russ White" <riw@cisco.com>,
        "Routing Protocols Security Working Group" <rpsec@ietf.org>
Subject: RE: [RPSEC] Threats Draft Issues: Where we Stand?
Date: Fri, 25 Jul 2003 22:57:38 -0500
Message-ID: <OPEAIGKIBEEBLAPGJAMBGEJMCDAA.dhuang@conrel.sice.umkc.edu>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.6604 (9.0.2911.0)
In-Reply-To: <Pine.WNT.4.55.0307252202210.908@russpc>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
X-OriginalArrivalTime: 26 Jul 2003 04:00:56.0914 (UTC) FILETIME=[8441C320:01C3532A]
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

> Issue 6: Section 4.7 Is overload a legitimate attack against a routing
> protocol?
>
> Status: Thus far, we have Jeff, Jean-Jacques, and I arguing against it
> being a threat, and Alex A arguing it is a threat. What's the concensus on
> this one? I'm inclined to all it not a threat based on the current
> arguments.

I think we should leave the overload to control plane. This based on several
facts. 1. The threat draft is not only for TCP/IP type based routing
protocols.
Some routing protocol may have separate channels to take only routing
traffic.
2. Even based on TCP/IP protocol stack and in-band routing, when the "data"
is
destine to the port used by routing process, the router will consider the
"data" is
routing data. Since I think the router will forward the "data" to the
routing
process. 3. Moreover, I am thinking good protocol design will help to
minimize
the effect of control plane based overloading. For example, a routing
protocol
is lack of authentication protection. The overloaded traffic might be
amplified
due to flooding. Thus, when you designing a routing protocol, you should be
cautious, how strong/complicated the authentication scheme is, and
what kind of routing scheme is used, such as flooding/selective flooding.
Although
you might not totally prevent the overload attack, you could decrease the
overloading
effect of overall routing domain.

Based on these facts, I think the overload should be there in the control
plane
level.


Dijiang


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sat Jul 26 06:55:38 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03297
	for <rpsec-archive@odin.ietf.org>; Sat, 26 Jul 2003 06:55:38 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gMhl-0006xN-N7
	for rpsec-archive@odin.ietf.org; Sat, 26 Jul 2003 06:55:14 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6QAtDXn026742
	for rpsec-archive@odin.ietf.org; Sat, 26 Jul 2003 06:55:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gMhl-0006xF-EW
	for rpsec-web-archive@optimus.ietf.org; Sat, 26 Jul 2003 06:55:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03276
	for <rpsec-web-archive@ietf.org>; Sat, 26 Jul 2003 06:55:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gMhh-00079z-00
	for rpsec-web-archive@ietf.org; Sat, 26 Jul 2003 06:55:09 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gMhg-00079w-00
	for rpsec-web-archive@ietf.org; Sat, 26 Jul 2003 06:55:08 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gMhZ-0006vp-85; Sat, 26 Jul 2003 06:55:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gMgr-0006v0-8l
	for rpsec@optimus.ietf.org; Sat, 26 Jul 2003 06:54:17 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03255
	for <rpsec@ietf.org>; Sat, 26 Jul 2003 06:54:10 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gMgn-000793-00
	for rpsec@ietf.org; Sat, 26 Jul 2003 06:54:13 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gMgm-00078J-00
	for rpsec@ietf.org; Sat, 26 Jul 2003 06:54:12 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP
	id 4DBA833A49; Sat, 26 Jul 2003 12:53:43 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP
	id 2C4EF3F478; Sat, 26 Jul 2003 12:54:04 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003072612534204945
 ; Sat, 26 Jul 2003 12:53:42 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP
	id CC9543F478; Sat, 26 Jul 2003 12:54:03 +0200 (CEST)
Received: from jjp by localhost with local id 19gMg9-0000lA-00; Sat, 26 Jul 2003 12:53:33 +0200
Date: Sat, 26 Jul 2003 12:53:33 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: Alex Audu <alex.audu@alcatel.com>
Cc: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030726105333.GA17773@ivan.int-evry.fr>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr> <3F217C07.15160537@alcatel.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3F217C07.15160537@alcatel.com>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Fri, Jul 25, 2003 at 01:50:47PM -0500, Alex Audu wrote:
>  The fact that you can indirectly attack the control by attacking the data
> plane
> doesn't lessen the ramification that  it could be a threat to routing
> functions. I think
> this should be mentioned in the threat document.

Regarding the overloading threat section, I rally myself to this
position (extracted from the draft):
   This section combines overload of the control plane and the data
   plane (the control and data plane of the router, I presume, i.e., the
   routing protocol messages and the data traffic, not the control and
   data plane of the routing protocol itself as discussed in section
   2.1).

This, in order to state about which definition of the data plane we're
dealing with in this discussion.

The routing protocol (rp) design may help against the overload of the
rp's data plane part. But I do not see how it may prevent routing device
data plane overload (unless you insert in your routing protocol mesg to
negociate bandwith allocation between peers for the rp itself; but this
is the responsibility of another protocol IMO)

I think we should focus (in this draft) on direct attacks against the
rp.  I certainly agree that data plane overload threatens the routing
functions, but so does switching off the power supply of the device, or
cutting the fiber or hitting the device with a bat.

BUT I agree overload is a threat against routing functions and I agree
this kind of threats should be documented somewhere. Yet this draft is ,
IMHO, not the appropriate place, and that's why I talked about the
possibility of having a document dealing with the security of routing
devices.

> Designers should be able to refer to the threat document to help them
> develop
> more threat-safe routing devices.

This is the whole pb: I don't think the threat document has the purpose
of helping in the development of devices, but of allowing proper
evaluation of current routing protocols and good design of future ones.

Because I wasn't sure about it, I had a look at the WG charter and felt
a bit confused: It introduces the need for documented routing security
requirements (which includes both our point of view), states the scope
is router-to-router protocols and that the document should benefit for
routing protocol designers, and eventually enounces task of the WG is
firstly to document threat models for routing systems. As I'm not native
English speaker, may be I misunderstood here.

As a conclusion, may be we should address the requirements for:

A threats document related to routing protocols
A threats document related to routing devices / systems

If needed, such documents may get merged in a single at the last minute.

Does the WG think it would be suitable ?

> 
> One benefit of separating Control and Data planes is that it may afford the
> control plane somewhat of an isolated castle that could be more easily
> shielded from outside attacks. One could do things like having separate
> streams for data and control between control and forwarding planes. Also,
> rate limiting could be used to improve
> safety.

I can only agree here, though I don't think it is directly related to
the intrinsec security of the rp.

--
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Sun Jul 27 23:05:49 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA03429
	for <rpsec-archive@odin.ietf.org>; Sun, 27 Jul 2003 23:05:49 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gyKC-00014M-IJ
	for rpsec-archive@odin.ietf.org; Sun, 27 Jul 2003 23:05:24 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6S35O5D004104
	for rpsec-archive@odin.ietf.org; Sun, 27 Jul 2003 23:05:24 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gyKC-000146-4e
	for rpsec-web-archive@optimus.ietf.org; Sun, 27 Jul 2003 23:05:24 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA03410
	for <rpsec-web-archive@ietf.org>; Sun, 27 Jul 2003 23:05:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gyK7-0003Ab-00
	for rpsec-web-archive@ietf.org; Sun, 27 Jul 2003 23:05:19 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gyK7-0003AX-00
	for rpsec-web-archive@ietf.org; Sun, 27 Jul 2003 23:05:19 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gyJp-00011W-H3; Sun, 27 Jul 2003 23:05:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19gyIu-0000zP-UZ
	for rpsec@optimus.ietf.org; Sun, 27 Jul 2003 23:04:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA03367
	for <rpsec@ietf.org>; Sun, 27 Jul 2003 23:03:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gyIq-00039x-00
	for rpsec@ietf.org; Sun, 27 Jul 2003 23:04:01 -0400
Received: from dns.nexthop.com ([65.247.36.216] helo=presque.nexthop.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19gyIq-00039W-00
	for rpsec@ietf.org; Sun, 27 Jul 2003 23:04:00 -0400
Received: (from root@localhost)
	by presque.nexthop.com (8.12.9/8.11.1) id h6S33HdJ028247;
	Sun, 27 Jul 2003 23:03:17 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: from jhaas.nexthop.com (jhaas.nexthop.com [65.247.36.31])
	by presque.nexthop.com (8.12.9/8.12.8) with ESMTP id h6S33AHr028240;
	Sun, 27 Jul 2003 23:03:10 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: (from jhaas@localhost)
	by jhaas.nexthop.com (8.11.3nb1/8.11.3) id h6S335s05264;
	Sun, 27 Jul 2003 23:03:05 -0400 (EDT)
Date: Sun, 27 Jul 2003 23:03:05 -0400
From: Jeffrey Haas <jhaas@nexthop.com>
To: Russ White <riw@cisco.com>
Cc: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030727230305.B5186@nexthop.com>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr> <3F217C07.15160537@alcatel.com> <Pine.WNT.4.55.0307252154320.908@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <Pine.WNT.4.55.0307252154320.908@russpc>; from ruwhite@cisco.com on Fri, Jul 25, 2003 at 09:59:10PM -0400
X-Virus-Scanned: by AMaViS perl-11
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Fri, Jul 25, 2003 at 09:59:10PM -0400, Russ White wrote:
> I tend to diagree--this is at a lower layer, and we shouldn'tneed to
> mention every possible lower layer attack.

Mostly, this is just a specific form of DoS attack.  It is 
very casually worth mentioning because an implementor may choose
to put some form of QoS into their data plane to guarantee that
control traffic makes it through.

> For instance, gaining access to
> the console can also get you into a position to attack the routing system,
> but I'm not certain we should include that in the threat analysis.

One can be done remotely, the other one cannot.

And no, sending in a ninja death squad to attack the actual hardware
doesn't count as a legitimately documentable threat.

> I don't think the conclusion that separating the data plane from the
> control plane is much help in preventing port flooding attacks. The router
> still has to receive packets in order to run a routing protocol; seperating
> the data plane from the control plane isn't going to stop an attacker from
> attacking thosse ports open for a router to receive packets.

As I'm sure you're aware, NOC's often keep an administrative ethernet
segment that is not on the forwarding plane of customer traffic.
This means that their customer links can be utterly saturated and 
otherwise unusable and yet the box may be administered through this
backdoor.

Control traffic could in some sense be done in a similar fashion.
The main thing that keeps us from doing this is the need to tightly
bind the circuit and the state of that circuit into the routing state.

A mechanism of some form that allowed a circuit of some form to
be partitioned such that it had guaranteed bandwidth for control
traffic would remove, or at least distance, the control plane from
a "data plane" DoS.

> Seperating the data and control plane is a good characteristic in many
> situations, but as a method to provide security, I'm not certain it
> actually helps anything (?).

I forget - exactly how did we choose to document DoS cases in the
document?  If all DoS is out of scope, then this is certainly
out of scope.  If not, it is worth considering - but not spending
a serious amount of time on.  To do so would tread very closely
on implementation details.

-- 
Jeff Haas 
NextHop Technologies

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 10:14:17 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA02580
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 10:14:17 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8l5-0007Cr-H9
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:13:51 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SEDpSw027700
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:13:51 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8l5-0007Ch-A2
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 10:13:51 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA02519
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 10:13:46 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8l2-0002ji-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:13:48 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8l1-0002je-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:13:47 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8kG-00076p-Sy; Mon, 28 Jul 2003 10:13:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8jV-00075v-VT
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 10:12:14 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA02366
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 10:12:09 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8jT-0002iX-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:12:11 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8jT-0002iF-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:12:11 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-3.cisco.com with ESMTP; 28 Jul 2003 07:11:40 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6SEBcMK016653;
	Mon, 28 Jul 2003 10:11:38 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-551.cisco.com [10.82.226.39])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id KAA26652;
	Mon, 28 Jul 2003 10:11:37 -0400 (EDT)
Date: Mon, 28 Jul 2003 10:11:37 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
cc: Alex Audu <alex.audu@alcatel.com>, rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <20030726105333.GA17773@ivan.int-evry.fr>
Message-ID: <Pine.WNT.4.55.0307281007530.700@russpc>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
 <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
 <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> BUT I agree overload is a threat against routing functions and I agree
> this kind of threats should be documented somewhere. Yet this draft is ,
> IMHO, not the appropriate place, and that's why I talked about the
> possibility of having a document dealing with the security of routing
> devices.

Right.... The issue, to me, is not whether or not this is a legitimate
threat against the routing system, but rather we should include this sort
of a threat here?

I think Jeff has argued for mentioning it, but not going into great detail.
There may be some value in having a section where we mention things like
this, but don't go into detail. It would be analogous to the sections in
the BGP attack tree that talk about things "outside" the actual attack tree
as possible attacks, but it's not an actual attack that this specific
document goes into detail on.

:-)

Russ


__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 10:24:09 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03075
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 10:24:09 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8ud-0007dG-O8
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:23:43 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SENh6k029332
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:23:43 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8ud-0007d1-Ju
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 10:23:43 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03051
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 10:23:38 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8ub-0002pY-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:23:41 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8ua-0002pV-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:23:40 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8tw-0007Xc-DY; Mon, 28 Jul 2003 10:23:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8tB-0007Rz-JT
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 10:22:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA02973
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 10:22:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8t9-0002o5-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:22:11 -0400
Received: from dns.nexthop.com ([65.247.36.216] helo=presque.nexthop.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8t8-0002nW-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:22:10 -0400
Received: (from root@localhost)
	by presque.nexthop.com (8.12.9/8.11.1) id h6SELUrc041346;
	Mon, 28 Jul 2003 10:21:30 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: from jhaas.nexthop.com (jhaas.nexthop.com [65.247.36.31])
	by presque.nexthop.com (8.12.9/8.12.8) with ESMTP id h6SELPHr041339;
	Mon, 28 Jul 2003 10:21:25 -0400 (EDT)
	(envelope-from jhaas@jhaas.nexthop.com)
Received: (from jhaas@localhost)
	by jhaas.nexthop.com (8.11.3nb1/8.11.3) id h6SELKo07418;
	Mon, 28 Jul 2003 10:21:20 -0400 (EDT)
Date: Mon, 28 Jul 2003 10:21:20 -0400
From: Jeffrey Haas <jhaas@nexthop.com>
To: Russ White <riw@cisco.com>
Cc: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030728102120.A7361@nexthop.com>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr> <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr> <Pine.WNT.4.55.0307281007530.700@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <Pine.WNT.4.55.0307281007530.700@russpc>; from ruwhite@cisco.com on Mon, Jul 28, 2003 at 10:11:37AM -0400
X-Virus-Scanned: by AMaViS perl-11
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Mon, Jul 28, 2003 at 10:11:37AM -0400, Russ White wrote:
> I think Jeff has argued for mentioning it, but not going into great detail.

Basically:
"Denial of service and resource starvation are two attacks against
a routing system.  Unless the mechanisms used in these attacks
are capable of being dealt with by changes to the protocol, such
attacks are outside the scope of this document."

-- 
Jeff Haas 
NextHop Technologies

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 10:31:12 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03266
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 10:31:11 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h90R-0007sZ-52
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:29:43 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SETh9h030283
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:29:43 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h90R-0007sM-0m
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 10:29:43 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03213
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 10:29:38 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h90O-0002si-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:29:40 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h90O-0002sf-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:29:40 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8zl-0007mP-5q; Mon, 28 Jul 2003 10:29:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h8z8-0007m3-9e
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 10:28:22 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03191
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 10:28:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8z4-0002s0-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:28:18 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h8z4-0002rr-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:28:18 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-2.cisco.com with ESMTP; 28 Jul 2003 07:30:11 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6SERiMK020075;
	Mon, 28 Jul 2003 10:27:45 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-551.cisco.com [10.82.226.39])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id KAA27903;
	Mon, 28 Jul 2003 10:27:44 -0400 (EDT)
Date: Mon, 28 Jul 2003 10:27:44 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Jeffrey Haas <jhaas@nexthop.com>
cc: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <20030728102120.A7361@nexthop.com>
Message-ID: <Pine.WNT.4.55.0307281027371.700@russpc>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
 <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
 <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr>
 <Pine.WNT.4.55.0307281007530.700@russpc> <20030728102120.A7361@nexthop.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


This sounds fine to me....

:-)

Russ

On Mon, 28 Jul 2003, Jeffrey Haas wrote:

> On Mon, Jul 28, 2003 at 10:11:37AM -0400, Russ White wrote:
> > I think Jeff has argued for mentioning it, but not going into great detail.
>
> Basically:
> "Denial of service and resource starvation are two attacks against
> a routing system.  Unless the mechanisms used in these attacks
> are capable of being dealt with by changes to the protocol, such
> attacks are outside the scope of this document."
>
> --
> Jeff Haas
> NextHop Technologies
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 10:44:09 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03581
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 10:44:09 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9E0-0000D9-A4
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:43:44 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SEhiEo000805
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 10:43:44 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9E0-0000Cu-6u
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 10:43:44 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03569
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 10:43:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9Dx-00030k-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:43:41 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9Dx-00030h-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 10:43:41 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9DI-00008x-5Z; Mon, 28 Jul 2003 10:43:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9Cf-0008WA-P3
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 10:42:21 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03487
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 10:42:16 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9Cd-0002zP-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:42:19 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9Cc-0002zA-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 10:42:18 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP id 5BC4233A83
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 16:41:33 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP id F1CDC3F469
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 16:42:40 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003072816413229449
 for <rpsec@ietf.org>; Mon, 28 Jul 2003 16:41:32 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP id D1FA33F427
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 16:42:40 +0200 (CEST)
Received: from jjp by localhost with local id 19h9Ba-0001A5-00
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 16:41:14 +0200
Date: Mon, 28 Jul 2003 16:41:14 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030728144114.GA4440@ivan.int-evry.fr>
Mail-Followup-To: rpsec@ietf.org
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr> <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr> <Pine.WNT.4.55.0307281007530.700@russpc> <20030728102120.A7361@nexthop.com> <Pine.WNT.4.55.0307281027371.700@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.WNT.4.55.0307281027371.700@russpc>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Mon, Jul 28, 2003 at 10:27:44AM -0400, Russ White wrote:
> > On Mon, Jul 28, 2003 at 10:11:37AM -0400, Russ White wrote:
> > > I think Jeff has argued for mentioning it, but not going into great detail.
> >
> > Basically:
> > "Denial of service and resource starvation are two attacks against
> > a routing system.  Unless the mechanisms used in these attacks
> > are capable of being dealt with by changes to the protocol, such
> > attacks are outside the scope of this document."

Ok for me: this is a clear statement of that it is both a threat and
outside the scope of the doc.

-- 
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 11:32:41 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA07508
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 11:32:41 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9yu-0002d1-69
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 11:32:13 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SFWC9Z010099
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 11:32:12 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9yu-0002co-35
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 11:32:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA07472
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 11:32:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9yt-0004Bg-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 11:32:11 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9ys-0004Bd-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 11:32:10 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9yj-0002af-OW; Mon, 28 Jul 2003 11:32:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19h9xz-0002Y6-Ux
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 11:31:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA07373
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 11:31:10 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9xx-00049P-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 11:31:13 -0400
Received: from auds952.usa.alcatel.com ([143.209.238.7])
	by ietf-mx with esmtp (Exim 4.12)
	id 19h9xw-00048a-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 11:31:12 -0400
Received: from alcatel.com (localhost [127.0.0.1])
	by auds952.usa.alcatel.com (8.12.8p1/8.12.8) with ESMTP id h6SFUVB3024139;
	Mon, 28 Jul 2003 10:30:31 -0500 (CDT)
Message-ID: <3F254197.A40CF71C@alcatel.com>
Date: Mon, 28 Jul 2003 10:30:31 -0500
From: Alex Audu <alex.audu@alcatel.com>
Reply-To: alex.audu@alcatel.com
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Russ White <riw@cisco.com>
CC: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>,
        Jeffrey Haas <jhaas@nexthop.com>,
        Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
	 <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
	 <3F217C07.15160537@alcatel.com> <Pine.WNT.4.55.0307252154320.908@russpc>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Russ,  I am not sure if the console is a core part of a routing device.
So,..stretching that argument to include a console is a big stretch.

One way to attack the routing protocol is to slow it down by starving  it
of  processing cycles. If the forwarding and control functions are being
handled by the same processor, then the control can be directly affected by
flooding the ports with data. Separating the control decouples the
procesing cycles,..and improves the survivability of the control. How
effective that is depends on the design.

Regards,
Alex.


Russ White wrote:

> > The fact that you can indirectly attack the control by attacking the data
> > plane doesn't lessen the ramification that it could be a threat to
> > routing functions. I think this should be mentioned in the threat
> > document.
> >
> > Designers should be able to refer to the threat document to help them
> > develop more threat-safe routing devices.
>
> I tend to diagree--this is at a lower layer, and we shouldn'tneed to
> mention every possible lower layer attack. For instance, gaining access to
> the console can also get you into a position to attack the routing system,
> but I'm not certain we should include that in the threat analysis.
>
> > One benefit of separating Control and Data planes is that it may afford
> > the control plane somewhat of an isolated castle that could be more
> > easily shielded from outside attacks. One could do things like having
> > separate streams for data and control between control and forwarding
> > planes. Also, rate limiting could be used to improve safety.
>
> I don't think the conclusion that separating the data plane from the
> control plane is much help in preventing port flooding attacks. The router
> still has to receive packets in order to run a routing protocol; seperating
> the data plane from the control plane isn't going to stop an attacker from
> attacking thosse ports open for a router to receive packets.
>
> Seperating the data and control plane is a good characteristic in many
> situations, but as a method to provide security, I'm not certain it
> actually helps anything (?).
>
> :-)
>
> Russ
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 12:29:38 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11507
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 12:29:38 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hAs4-0005GJ-Te
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 12:29:12 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SGTC6O020221
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 12:29:12 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hAs4-0005G4-QY
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 12:29:12 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11445
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 12:29:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hAs3-0005Sz-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 12:29:11 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hAs2-0005Su-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 12:29:10 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hArs-0005Bi-JR; Mon, 28 Jul 2003 12:29:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hArB-00058c-Sp
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 12:28:17 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11350
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 12:28:12 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hApD-0005RR-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 12:26:15 -0400
Received: from auds953.usa.alcatel.com ([143.209.238.6])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hApC-0005RE-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 12:26:14 -0400
Received: from alcatel.com (localhost [127.0.0.1])
	by auds953.usa.alcatel.com (8.12.8p1/8.12.8) with ESMTP id h6SGPXLX025498;
	Mon, 28 Jul 2003 11:25:33 -0500 (CDT)
Message-ID: <3F254E7C.6CC44D6E@alcatel.com>
Date: Mon, 28 Jul 2003 11:25:32 -0500
From: Alex Audu <alex.audu@alcatel.com>
Reply-To: alex.audu@alcatel.com
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
CC: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc> <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr> <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Hi Jean-Jacques,

I guess you are right about the fact that overload attacks may not reflect
accurately on the level of security  inherent in the routing protocol.  But I
believe
the job of the WG is to document the threats that contribute to the
problem space. Then let the designers take this document as input and worry
about the solution space for both routing protocol, and the routing device.

Regards,
Alex.

Jean-Jacques Puig wrote:

> On Fri, Jul 25, 2003 at 01:50:47PM -0500, Alex Audu wrote:
> >  The fact that you can indirectly attack the control by attacking the data
> > plane
> > doesn't lessen the ramification that  it could be a threat to routing
> > functions. I think
> > this should be mentioned in the threat document.
>
> Regarding the overloading threat section, I rally myself to this
> position (extracted from the draft):
>    This section combines overload of the control plane and the data
>    plane (the control and data plane of the router, I presume, i.e., the
>    routing protocol messages and the data traffic, not the control and
>    data plane of the routing protocol itself as discussed in section
>    2.1).
>
> This, in order to state about which definition of the data plane we're
> dealing with in this discussion.
>
> The routing protocol (rp) design may help against the overload of the
> rp's data plane part. But I do not see how it may prevent routing device
> data plane overload (unless you insert in your routing protocol mesg to
> negociate bandwith allocation between peers for the rp itself; but this
> is the responsibility of another protocol IMO)
>
> I think we should focus (in this draft) on direct attacks against the
> rp.  I certainly agree that data plane overload threatens the routing
> functions, but so does switching off the power supply of the device, or
> cutting the fiber or hitting the device with a bat.
>
> BUT I agree overload is a threat against routing functions and I agree
> this kind of threats should be documented somewhere. Yet this draft is ,
> IMHO, not the appropriate place, and that's why I talked about the
> possibility of having a document dealing with the security of routing
> devices.
>
> > Designers should be able to refer to the threat document to help them
> > develop
> > more threat-safe routing devices.
>
> This is the whole pb: I don't think the threat document has the purpose
> of helping in the development of devices, but of allowing proper
> evaluation of current routing protocols and good design of future ones.
>
> Because I wasn't sure about it, I had a look at the WG charter and felt
> a bit confused: It introduces the need for documented routing security
> requirements (which includes both our point of view), states the scope
> is router-to-router protocols and that the document should benefit for
> routing protocol designers, and eventually enounces task of the WG is
> firstly to document threat models for routing systems. As I'm not native
> English speaker, may be I misunderstood here.
>
> As a conclusion, may be we should address the requirements for:
>
> A threats document related to routing protocols
> A threats document related to routing devices / systems
>
> If needed, such documents may get merged in a single at the last minute.
>
> Does the WG think it would be suitable ?
>
> >
> > One benefit of separating Control and Data planes is that it may afford the
> > control plane somewhat of an isolated castle that could be more easily
> > shielded from outside attacks. One could do things like having separate
> > streams for data and control between control and forwarding planes. Also,
> > rate limiting could be used to improve
> > safety.
>
> I can only agree here, though I don't think it is directly related to
> the intrinsec security of the rp.
>
> --
> Jean-Jacques Puig
>
> [homepage] http://www-lor.int-evry.fr/~puig/


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 12:47:09 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11986
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 12:47:09 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hB90-00063i-Cr
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 12:46:43 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SGkgaQ023284
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 12:46:42 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hB90-00063T-9X
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 12:46:42 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11983
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 12:46:36 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hB8y-0005a2-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 12:46:40 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hB8x-0005Zz-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 12:46:39 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hB8L-000626-HX; Mon, 28 Jul 2003 12:46:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hB7N-00060v-23
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 12:45:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11963
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 12:44:56 -0400 (EDT)
From: ram.gopal@nokia.com
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hB7L-0005Zh-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 12:44:59 -0400
Received: from [63.78.179.217] (helo=mgw-dax2.ext.nokia.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hB7K-0005ZX-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 12:44:58 -0400
Received: from davir02nok.americas.nokia.com (davir02nok.americas.nokia.com [172.18.242.85])
	by mgw-dax2.ext.nokia.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id h6SGisG13159
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 11:44:54 -0500 (CDT)
Received: from daebh001.NOE.Nokia.com (unverified) by davir02nok.americas.nokia.com
 (Content Technologies SMTPRS 4.2.5) with ESMTP id <T63b52269b3ac12f255141@davir02nok.americas.nokia.com>;
 Mon, 28 Jul 2003 11:44:53 -0500
Received: from bsebe001.NOE.Nokia.com ([172.19.160.13]) by daebh001.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139);
	 Mon, 28 Jul 2003 09:44:42 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.0.6375.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Date: Mon, 28 Jul 2003 12:44:41 -0400
Message-ID: <DC504E9C3384054C8506D3E6BB012460013879BF@bsebe001.americas.nokia.com>
Thread-Topic: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Thread-Index: AcNVEnKxGEQluCueSh+f2i0++ZsZgAAFIxcQ
To: <riw@cisco.com>, <Jean-Jacques.Puig@int-evry.fr>
Cc: <alex.audu@alcatel.com>, <rpsec@ietf.org>
X-OriginalArrivalTime: 28 Jul 2003 16:44:42.0873 (UTC) FILETIME=[8B7BAE90:01C35527]
Content-Transfer-Encoding: quoted-printable
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: quoted-printable
Content-Transfer-Encoding: quoted-printable

Comments are inline

> -----Original Message-----
> From: ext Russ White [mailto:ruwhite@cisco.com]
> Sent: Monday, July 28, 2003 10:12 AM
> To: Jean-Jacques Puig
> Cc: Alex Audu; rpsec@ietf.org
> Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
>=20
>=20
>=20
> > BUT I agree overload is a threat against routing functions=20
> and I agree
> > this kind of threats should be documented somewhere. Yet=20
> this draft is ,
> > IMHO, not the appropriate place, and that's why I talked about the
> > possibility of having a document dealing with the security=20
> of routing
> > devices.
>=20
> Right.... The issue, to me, is not whether or not this is a legitimate
> threat against the routing system, but rather we should=20
> include this sort
> of a threat here?
>=20
> I think Jeff has argued for mentioning it, but not going into=20
> great detail.
> There may be some value in having a section where we mention=20
> things like
> this, but don't go into detail. It would be analogous to the=20
> sections in
> the BGP attack tree that talk about things "outside" the=20
> actual attack tree
> as possible attacks, but it's not an actual attack that this specific
> document goes into detail on.
=20
Yes, when we analyse the threats against the routing functions we may =
come across threats
that may compromise the routing platform itself. We should document at =
least highlight those
detail without going into details.


regards
Ramg=20

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 13:11:40 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA12999
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 13:11:40 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBWk-00074R-Mi
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 13:11:15 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SHBEsu027175
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 13:11:14 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBWk-00074E-IZ
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 13:11:14 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA12891
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 13:11:09 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBWi-0005pD-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 13:11:12 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBWh-0005pA-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 13:11:11 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBWY-00070g-2E; Mon, 28 Jul 2003 13:11:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBVa-000705-6w
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 13:10:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA12859
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 13:09:57 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBVY-0005oO-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 13:10:00 -0400
Received: from law10-oe66.law10.hotmail.com ([64.4.14.201] helo=hotmail.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBVX-0005nN-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 13:09:59 -0400
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
	 Mon, 28 Jul 2003 10:09:28 -0700
Received: from 67.81.210.146 by law10-oe66.law10.hotmail.com with DAV;
	Mon, 28 Jul 2003 17:09:28 +0000
X-Originating-IP: [67.81.210.146]
X-Originating-Email: [piyush_bhatnagar@hotmail.com]
From: "Piyush Bhatnagar" <piyush_bhatnagar@hotmail.com>
To: <ram.gopal@nokia.com>, <riw@cisco.com>, <Jean-Jacques.Puig@int-evry.fr>
Cc: <alex.audu@alcatel.com>, <rpsec@ietf.org>
References: <DC504E9C3384054C8506D3E6BB012460013879BF@bsebe001.americas.nokia.com>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Date: Mon, 28 Jul 2003 13:09:36 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1158
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Message-ID: <Law10-OE66GA39SEkm2000070fe@hotmail.com>
X-OriginalArrivalTime: 28 Jul 2003 17:09:28.0924 (UTC) FILETIME=[013D11C0:01C3552B]
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Well, I may agree that this is not the appropriate place for
discussion/documentation of threats that compromise the routing platform,
but such threats can have a much more damaging effect. So we should try and
document such threats as well either in this doc or in another doc
addressing threats that can compromise the routing platform itself.
-
Regards, Piyush
==========================
Piyush Bhatnagar, CISSP
piyush_bhatnagar@hotmail.com
==========================

----- Original Message ----- 
From: <ram.gopal@nokia.com>
To: <riw@cisco.com>; <Jean-Jacques.Puig@int-evry.fr>
Cc: <alex.audu@alcatel.com>; <rpsec@ietf.org>
Sent: Monday, July 28, 2003 12:44 PM
Subject: RE: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload


Comments are inline

> -----Original Message-----
> From: ext Russ White [mailto:ruwhite@cisco.com]
> Sent: Monday, July 28, 2003 10:12 AM
> To: Jean-Jacques Puig
> Cc: Alex Audu; rpsec@ietf.org
> Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
>
>
>
> > BUT I agree overload is a threat against routing functions
> and I agree
> > this kind of threats should be documented somewhere. Yet
> this draft is ,
> > IMHO, not the appropriate place, and that's why I talked about the
> > possibility of having a document dealing with the security
> of routing
> > devices.
>
> Right.... The issue, to me, is not whether or not this is a legitimate
> threat against the routing system, but rather we should
> include this sort
> of a threat here?
>
> I think Jeff has argued for mentioning it, but not going into
> great detail.
> There may be some value in having a section where we mention
> things like
> this, but don't go into detail. It would be analogous to the
> sections in
> the BGP attack tree that talk about things "outside" the
> actual attack tree
> as possible attacks, but it's not an actual attack that this specific
> document goes into detail on.

Yes, when we analyse the threats against the routing functions we may come
across threats
that may compromise the routing platform itself. We should document at least
highlight those
detail without going into details.


regards
Ramg

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 13:31:40 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAB13533
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 13:31:40 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBq5-0007aK-63
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 13:31:13 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SHVDcq029150
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 13:31:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBq5-0007a5-31
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 13:31:13 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA13512
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 13:31:09 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBq3-00060L-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 13:31:11 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBq2-00060I-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 13:31:10 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBpt-0007Y9-Rf; Mon, 28 Jul 2003 13:31:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hBpe-0007XZ-TC
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 13:30:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA13479
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 13:30:43 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBpc-000601-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 13:30:44 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hBpc-0005zk-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 13:30:44 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-2.cisco.com with ESMTP; 28 Jul 2003 10:32:39 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6SHUBMK029202
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 13:30:11 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-551.cisco.com [10.82.226.39])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id NAA12679
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 13:30:11 -0400 (EDT)
Date: Mon, 28 Jul 2003 13:30:11 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <Pine.WNT.4.55.0307281027371.700@russpc>
Message-ID: <Pine.WNT.4.55.0307281329400.2660@russpc>
References: <Pine.WNT.4.55.0307132208080.1416@russpc> <Pine.WNT.4.55.0307132236030.1416@russpc>
 <20030721093219.B1126@nexthop.com> <20030724135501.GC17957@ivan.int-evry.fr>
 <3F217C07.15160537@alcatel.com> <20030726105333.GA17773@ivan.int-evry.fr>
 <Pine.WNT.4.55.0307281007530.700@russpc> <20030728102120.A7361@nexthop.com>
 <Pine.WNT.4.55.0307281027371.700@russpc>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


So, could we build concensus around the text that Jeff proposed below? Or
does someone object to this, would like to change it, etc?

:-)

Russ

On Mon, 28 Jul 2003, Russ White wrote:

>
> This sounds fine to me....
>
> :-)
>
> Russ
>
> On Mon, 28 Jul 2003, Jeffrey Haas wrote:
>
> > On Mon, Jul 28, 2003 at 10:11:37AM -0400, Russ White wrote:
> > > I think Jeff has argued for mentioning it, but not going into great detail.
> >
> > Basically:
> > "Denial of service and resource starvation are two attacks against
> > a routing system.  Unless the mechanisms used in these attacks
> > are capable of being dealt with by changes to the protocol, such
> > attacks are outside the scope of this document."
> >
> > --
> > Jeff Haas
> > NextHop Technologies
> >
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone
>
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Mon Jul 28 14:16:42 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA14861
	for <rpsec-archive@odin.ietf.org>; Mon, 28 Jul 2003 14:16:42 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hCXf-0001YW-Ug
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 14:16:16 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6SIGFa7005974
	for rpsec-archive@odin.ietf.org; Mon, 28 Jul 2003 14:16:15 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hCXf-0001YH-RT
	for rpsec-web-archive@optimus.ietf.org; Mon, 28 Jul 2003 14:16:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA14847
	for <rpsec-web-archive@ietf.org>; Mon, 28 Jul 2003 14:16:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hCXd-0006Od-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 14:16:13 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hCXc-0006Oa-00
	for rpsec-web-archive@ietf.org; Mon, 28 Jul 2003 14:16:12 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hCXR-0001WL-3K; Mon, 28 Jul 2003 14:16:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hCWV-0001VB-Uj
	for rpsec@optimus.ietf.org; Mon, 28 Jul 2003 14:15:03 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA14790
	for <rpsec@ietf.org>; Mon, 28 Jul 2003 14:14:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hCWT-0006Nu-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 14:15:01 -0400
Received: from brmea-mail-3.sun.com ([192.18.98.34])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hCWR-0006Nh-00
	for rpsec@ietf.org; Mon, 28 Jul 2003 14:15:00 -0400
Received: from sydney.East.Sun.COM ([129.148.9.16])
	by brmea-mail-3.sun.com (8.12.9/8.12.9) with ESMTP id h6SIEu7h015732;
	Mon, 28 Jul 2003 12:14:56 -0600 (MDT)
Received: from sr1-ubur-05 (sr1-ubur-05 [129.148.9.84])
	by sydney.East.Sun.COM (8.11.7+Sun/8.11.7/ENSMAIL,v2.2) with SMTP id h6SIEus16556;
	Mon, 28 Jul 2003 14:14:56 -0400 (EDT)
Message-Id: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
Date: Mon, 28 Jul 2003 14:14:56 -0400 (EDT)
From: Radia Perlman - Boston Center for Networking <Radia.Perlman@Sun.COM>
Reply-To: Radia Perlman - Boston Center for Networking <Radia.Perlman@Sun.COM>
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
To: rpsec@ietf.org, riw@cisco.com
MIME-Version: 1.0
Content-Type: TEXT/plain; charset=us-ascii
Content-MD5: tSoupiuDkCxnqZOO3G0sKg==
X-Mailer: dtmail 1.3.0 @(#)CDE Version 1.5.3_06 SunOS 5.9 sun4u sparc 
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Someone poked me to comment, and I haven't
been following this thread. But it seems, unless I'm
misunderstanding the thread based on some samples I've read just
now, that my thesis is an existence proof that changes in
the routing protocol *can* be a defense against DOS and
resource starvation. So the statement:

>> Unless the mechanisms used in these attacks
> > are capable of being dealt with by changes to the protocol, such
> > attacks are outside the scope of this document."

seems as though DOS and resource starvation should be in scope.

And also, it seems as though if someone can cause resource starvation
and prevent packets from being delivered, who cares if the routing
protocol is creating correct forwarding tables?

Radia


	From: Russ White <ruwhite@cisco.com>

	
	So, could we build concensus around the text that Jeff proposed below? 
Or
	does someone object to this, would like to change it, etc?
	
	:-)
	
	Russ
	
	On Mon, 28 Jul 2003, Russ White wrote:
	
	>
	> This sounds fine to me....
	>
	> :-)
	>
	> Russ
	>
	> On Mon, 28 Jul 2003, Jeffrey Haas wrote:
	>
	> > On Mon, Jul 28, 2003 at 10:11:37AM -0400, Russ White wrote:
	> > > I think Jeff has argued for mentioning it, but not going into 
great detail.
	> >
	> > Basically:
	> > "Denial of service and resource starvation are two attacks against
	> > a routing system.  Unless the mechanisms used in these attacks
	> > are capable of being dealt with by changes to the protocol, such
	> > attacks are outside the scope of this document."
	> >
	> > --
	> > Jeff Haas
	> > NextHop Technologies
	> >
	>
	> __________________________________
	> riw@cisco.com CCIE <>< Grace Alone
	>
	>
	
	__________________________________
	riw@cisco.com CCIE <>< Grace Alone
	
	
	_______________________________________________
	RPSEC mailing list
	RPSEC@ietf.org
	https://www1.ietf.org/mailman/listinfo/rpsec


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Tue Jul 29 04:45:54 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA15803
	for <rpsec-archive@odin.ietf.org>; Tue, 29 Jul 2003 04:45:54 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hQ6r-0002ed-AI
	for rpsec-archive@odin.ietf.org; Tue, 29 Jul 2003 04:45:29 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6T8jT8Z010201
	for rpsec-archive@odin.ietf.org; Tue, 29 Jul 2003 04:45:29 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hQ6q-0002eS-7C
	for rpsec-web-archive@optimus.ietf.org; Tue, 29 Jul 2003 04:45:28 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA15794
	for <rpsec-web-archive@ietf.org>; Tue, 29 Jul 2003 04:45:22 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hQ6n-0003Xz-00
	for rpsec-web-archive@ietf.org; Tue, 29 Jul 2003 04:45:25 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19hQ6m-0003Xv-00
	for rpsec-web-archive@ietf.org; Tue, 29 Jul 2003 04:45:24 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hQ6Q-0002cq-95; Tue, 29 Jul 2003 04:45:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19hQ5V-0002c0-8i
	for rpsec@optimus.ietf.org; Tue, 29 Jul 2003 04:44:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA15766
	for <rpsec@ietf.org>; Tue, 29 Jul 2003 04:43:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hQ5S-0003Xa-00
	for rpsec@ietf.org; Tue, 29 Jul 2003 04:44:02 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hQ5R-0003XW-00
	for rpsec@ietf.org; Tue, 29 Jul 2003 04:44:01 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP id 5516534208
	for <rpsec@ietf.org>; Tue, 29 Jul 2003 10:41:24 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP id 394F33F435
	for <rpsec@ietf.org>; Tue, 29 Jul 2003 10:42:48 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003072910412413939
 for <rpsec@ietf.org>; Tue, 29 Jul 2003 10:41:24 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP id EB4163F435
	for <rpsec@ietf.org>; Tue, 29 Jul 2003 10:42:47 +0200 (CEST)
Received: from jjp by localhost with local id 19hQ2X-0008U7-00
	for <rpsec@ietf.org>; Tue, 29 Jul 2003 10:41:01 +0200
Date: Tue, 29 Jul 2003 10:41:01 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030729084101.GA4496@ivan.int-evry.fr>
Mail-Followup-To: rpsec@ietf.org
References: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

Hi !
	A short comment inline.

On Mon, Jul 28, 2003 at 02:14:56PM -0400, Radia Perlman - Boston Center for Networking wrote:
> Someone poked me to comment, and I haven't
> been following this thread. But it seems, unless I'm
> misunderstanding the thread based on some samples I've read just
> now, that my thesis is an existence proof that changes in
> the routing protocol *can* be a defense against DOS and
> resource starvation. So the statement:
> 
> >> Unless the mechanisms used in these attacks
> > > are capable of being dealt with by changes to the protocol, such
> > > attacks are outside the scope of this document."
> 
> seems as though DOS and resource starvation should be in scope.

Or that, in the end, the statement suffers from a bad formulation: may
be a threats document should not make assumptions about what changes in
a protocol are capable to deal with or not, and stand to threats
description according to the scope.

> And also, it seems as though if someone can cause resource starvation
> and prevent packets from being delivered, who cares if the routing
> protocol is creating correct forwarding tables?

Then it makes sense to consider that overloading is a more general
threat than a threat against the routing protocol.

General threats agains forwarding/routing devices are certainly indirect
threats against routing protocols if such a device runs such protocols,
but are also indirect threats against resource reservation protocols,
management protocols or whatever runs on the device. Thus a standalone
doc would provide reference for specific contexts and prevent redundant
work.

--
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 07:08:50 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20466
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 07:08:50 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBII-0002kZ-Gl
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 07:08:26 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VB8QEb010567
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 07:08:26 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBII-0002kM-AG
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 07:08:26 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20451
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 07:08:19 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBIE-0002HN-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 07:08:22 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBID-0002HJ-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 07:08:21 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBHt-0002gP-MT; Thu, 31 Jul 2003 07:08:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBHe-0002fC-SE
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 07:07:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20431
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 07:07:40 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBHa-0002Gk-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 07:07:42 -0400
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBHa-0002Gg-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 07:07:42 -0400
Received: from cisco.com (64.102.124.13)
  by sj-iport-3.cisco.com with ESMTP; 31 Jul 2003 04:07:14 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6VB7Axc016113;
	Thu, 31 Jul 2003 07:07:11 -0400 (EDT)
Received: from dhcp-64-102-60-208.cisco.com (dhcp-64-102-60-208.cisco.com [64.102.60.208])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id HAA29770;
	Thu, 31 Jul 2003 07:07:10 -0400 (EDT)
Date: Thu, 31 Jul 2003 07:08:05 -0400 (EDT)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Radia Perlman - Boston Center for Networking <Radia.Perlman@Sun.COM>
cc: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
Message-ID: <Pine.OSX.4.51.0307310706400.15647@dhcp-64-102-60-208.cisco.com>
References: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> Someone poked me to comment, and I haven't been following this thread.
> But it seems, unless I'm misunderstanding the thread based on some
> samples I've read just now, that my thesis is an existence proof that
> changes in the routing protocol *can* be a defense against DOS and
> resource starvation. So the statement:

Okay--so, if changing the routing protocol can actually prevent DOS attacks
against the devices running the routing protocol (not against the network,
per se, but against the routers), then we should include it as in scope.
But, it might be useful to have some draft that discusses how this is
possible.

:-)

Russ


__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 07:11:32 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20562
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 07:11:31 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBKt-0002zZ-LZ
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 07:11:07 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VBB7ho011495
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 07:11:07 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBKt-0002zK-Ig
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 07:11:07 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20555
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 07:11:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBKp-0002J6-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 07:11:03 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBKo-0002J3-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 07:11:02 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBKn-0002vh-3X; Thu, 31 Jul 2003 07:11:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iBJs-0002rV-FT
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 07:10:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA20522
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 07:09:57 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBJo-0002IL-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 07:10:00 -0400
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iBJn-0002Hq-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 07:09:59 -0400
Received: from cisco.com (64.102.124.12)
  by sj-iport-2.cisco.com with ESMTP; 31 Jul 2003 04:12:20 -0700
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-1.cisco.com (8.12.9/8.12.6) with ESMTP id h6VB9CXw002777;
	Thu, 31 Jul 2003 07:09:13 -0400 (EDT)
Received: from dhcp-64-102-60-208.cisco.com (dhcp-64-102-60-208.cisco.com [64.102.60.208])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id HAA29857;
	Thu, 31 Jul 2003 07:09:12 -0400 (EDT)
Date: Thu, 31 Jul 2003 07:10:06 -0400 (EDT)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
cc: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
In-Reply-To: <20030729084101.GA4496@ivan.int-evry.fr>
Message-ID: <Pine.OSX.4.51.0307310708380.15647@dhcp-64-102-60-208.cisco.com>
References: <200307281814.h6SIEus16556@sydney.East.Sun.COM>
 <20030729084101.GA4496@ivan.int-evry.fr>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


> Or that, in the end, the statement suffers from a bad formulation: may be
> a threats document should not make assumptions about what changes in a
> protocol are capable to deal with or not, and stand to threats
> description according to the scope.

But you have to make such assumptions, or all threats docs end up covering
everything, right? Then there would only be one threat doc in the world,
just a really big one... :-)

> > And also, it seems as though if someone can cause resource starvation
> > and prevent packets from being delivered, who cares if the routing
> > protocol is creating correct forwarding tables?
>
> Then it makes sense to consider that overloading is a more general
> threat than a threat against the routing protocol.
>
> General threats agains forwarding/routing devices are certainly indirect
> threats against routing protocols if such a device runs such protocols,
> but are also indirect threats against resource reservation protocols,
> management protocols or whatever runs on the device. Thus a standalone
> doc would provide reference for specific contexts and prevent redundant
> work.

Yes, so should it be in or out of scope for this doc, and should the wg
take on such a doc, since it isn't "rp specific," although it does impact
the operation of rp's?

:-)

Russ


__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 08:44:01 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA23109
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 08:44:01 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iCmN-0006mx-6D
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 08:43:35 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VChZFD026089
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 08:43:35 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iCmN-0006mi-30
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 08:43:35 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA23020
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 08:43:31 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iCmL-0003Bu-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 08:43:33 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iCmK-0003Bg-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 08:43:32 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iClp-0006Zv-69; Thu, 31 Jul 2003 08:43:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iClL-0006Yp-9i
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 08:42:31 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA22986
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 08:42:27 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iClK-0003BJ-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 08:42:30 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iClJ-0003B8-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 08:42:29 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP id F3279339BE
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:41:56 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP id CCA193F40C
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:44:07 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003073114415602502
 for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:41:56 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP id ABBFC3F40C
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:44:07 +0200 (CEST)
Received: from jjp by localhost with local id 19iCkG-0002B2-00
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:41:24 +0200
Date: Thu, 31 Jul 2003 14:41:24 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: rpsec@ietf.org
Subject: Re: [RPSEC] Re: Threats Draft Issue 6: Section 4.7 Overload
Message-ID: <20030731124124.GA18350@ivan.int-evry.fr>
Mail-Followup-To: rpsec@ietf.org
References: <200307281814.h6SIEus16556@sydney.East.Sun.COM> <20030729084101.GA4496@ivan.int-evry.fr> <Pine.OSX.4.51.0307310708380.15647@dhcp-64-102-60-208.cisco.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.OSX.4.51.0307310708380.15647@dhcp-64-102-60-208.cisco.com>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Thu, Jul 31, 2003 at 07:10:06AM -0400, Russ White wrote:
> 
> > Or that, in the end, the statement suffers from a bad formulation: may be
> > a threats document should not make assumptions about what changes in a
> > protocol are capable to deal with or not, and stand to threats
> > description according to the scope.
> 
> But you have to make such assumptions, or all threats docs end up covering
> everything, right? Then there would only be one threat doc in the world,
> just a really big one... :-)

I meant that foreseeing solutions to a problem should not influence
the statement of the problem itself. Saying:

''Unless the mechanisms used in these attacks are capable of being dealt
with by changes to the protocol, such attacks are outside the scope of
this document.''

may result in rejecting a pb because we are currently unaware of a
solution through changes to the protocol. It seems that we have a
(bad) natural propensity for evaluating pbs in terms of solutions.

It is sometimes (rarely) possible to proove that no solution can solve
a specific pb; nevertheless, this does not imply that the pb should not
be stated clearly: monitoring occurences of the pb may provide a place
for forensic analysis and legal (prosecutions) 'post-solutions'.

> 
> > > And also, it seems as though if someone can cause resource starvation
> > > and prevent packets from being delivered, who cares if the routing
> > > protocol is creating correct forwarding tables?
> >
> > Then it makes sense to consider that overloading is a more general
> > threat than a threat against the routing protocol.
> >
> > General threats agains forwarding/routing devices are certainly indirect
> > threats against routing protocols if such a device runs such protocols,
> > but are also indirect threats against resource reservation protocols,
> > management protocols or whatever runs on the device. Thus a standalone
> > doc would provide reference for specific contexts and prevent redundant
> > work.
> 
> Yes, so should it be in or out of scope for this doc, and should the wg
> take on such a doc, since it isn't "rp specific," although it does impact
> the operation of rp's?

If no-one is interested in having a general threats document, then these
threats having consequences on rp operations, they should be mentionned
in the rp threats doc. If we set for a general threats document, then
the rp threats doc should mention that general threats have already
been presented in the general threats doc. This may be considered as a
modularity issue.

Of course the WG can take on such a doc. And so can ANY WG effort
focusing on a threat analysis possibly including such threats. The
question is: which will do it first ? I think we can: current draft
provides already some content (this was the whole issue of this thread
wasn't it ?).			

-- 
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 09:38:37 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA25144
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 09:38:37 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iDdD-0000Mw-48
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 09:38:11 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VDcBvI001412
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 09:38:11 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iDdD-0000Mh-14
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 09:38:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA25085
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 09:38:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iDdB-0003mn-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 09:38:09 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iDdA-0003mk-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 09:38:08 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iDd3-0000J4-CO; Thu, 31 Jul 2003 09:38:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iDcW-0000Bn-SP
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 09:37:28 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA24973
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 09:37:24 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iDcV-0003lD-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 09:37:27 -0400
Received: from herculanum.int-evry.fr ([157.159.11.15])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iDcU-0003jb-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 09:37:26 -0400
Received: from sparte.int-evry.fr (spartebis.int-evry.fr [157.159.10.20])
	by herculanum.int-evry.fr (Postfix) with ESMTP id 204FA33AAF
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 15:36:56 +0200 (CEST)
Received: from alpes.int-evry.fr (alpes.int-evry.fr [157.159.10.19])
	by spartebis.int-evry.fr (Postfix) with SMTP id C56513F40C
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 15:39:07 +0200 (CEST)
Received: from sparte.int-evry.fr ([157.159.10.11])
 by alpes.int-evry.fr (SAVSMTP 3.0.0.44) with SMTP id M2003073115365620652
 for <rpsec@ietf.org>; Thu, 31 Jul 2003 15:36:56 +0200
Received: from localhost (ivan.int-evry.fr [157.159.100.48])
	by sparte.int-evry.fr (Postfix) with ESMTP id A228E3F40C
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 15:39:07 +0200 (CEST)
Received: from jjp by localhost with local id 19iDbT-0002J5-00
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 15:36:23 +0200
Date: Thu, 31 Jul 2003 15:36:23 +0200
From: Jean-Jacques Puig <Jean-Jacques.Puig@int-evry.fr>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Question on Section 3.1.2.1
Message-ID: <20030731133623.GA8457@ivan.int-evry.fr>
Mail-Followup-To: Routing Protocols Security Working Group <rpsec@ietf.org>
References: <Pine.WNT.4.55.0307132313180.1416@russpc>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.WNT.4.55.0307132313180.1416@russpc>
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>

On Sun, Jul 13, 2003 at 11:13:53PM -0400, Russ White wrote:
> 
> 3.1.2.1 Threat Consequence Zone
> 
>    A threat consequence zone covers an area within which the network
>    operations have been affected by the threat consequences.
> 
> I've never understood the consequences of a threat

Threat consequence definition comes from RFC 2828. Though IRL threats
MAY have consequences (blackmail), I think the original intent here was
threat action consequence, but we will have to cope with current
terminology.

> --do you mean the
> area within which network operation has been affected by the
> consequences of an attack? It seems to me what you're trying to say is
> the zone where network operations would be impacted by an attack if a
> given threat were exploited?

May I state it this way:

3.1.2.1 Threat Consequence Zone

	A threat consequence zone covers the area within which the network
	operations have been affected by threat actions.


-- 
Jean-Jacques Puig

[homepage] http://www-lor.int-evry.fr/~puig/

_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 14:32:14 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07444
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 14:32:14 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIDM-0007Hu-Kd
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 14:31:48 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VIVmOg028008
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 14:31:48 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIDM-0007Hf-GS
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 14:31:48 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07398
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 14:31:43 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIDJ-0006Py-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 14:31:45 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIDJ-0006Pv-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 14:31:45 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iICc-00076b-GA; Thu, 31 Jul 2003 14:31:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIBr-00074z-Vx
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 14:30:16 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07357
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:30:11 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIBp-0006P7-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 14:30:13 -0400
Received: from auds953.usa.alcatel.com ([143.209.238.6])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIBo-0006Os-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 14:30:12 -0400
Received: from alcatel.com (localhost [127.0.0.1])
	by auds953.usa.alcatel.com (8.12.8p1/8.12.8) with ESMTP id h6VITXLX010277;
	Thu, 31 Jul 2003 13:29:33 -0500 (CDT)
Message-ID: <3F29600C.C53D2291@alcatel.com>
Date: Thu, 31 Jul 2003 13:29:33 -0500
From: Alex Audu <alex.audu@alcatel.com>
Reply-To: alex.audu@alcatel.com
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Russ White <riw@cisco.com>
CC: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Section 3.1.1 Comments
References: <Pine.WNT.4.55.0307132311010.1416@russpc>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

The recommended change is good.  I'd leave the MANET example in also
since it doesn't hurt.

Regards,
Alex.

Russ White wrote:

> I think I originally asked this:
>
> Replace this:
>
>    neighbor. For example, in OSPF (that is, before the MD5 part was
>    added), OSPF speaks to all routers on the local link that answer to
>    the AllSPFRouters multicast address.  Furthermore, MANET protocols
>    frequently speak over the broadcast link.
>
> with:
>
> For example, an OSPF router will form a peering relationship with any
> attached device which appears to be running OSPF, unless MD5
> authentication (or some other means) is used to prevent the peering
> relationship from forming.
>
> I'd pull the manet example, one is enough here, and reference the OSPF
> MD5 draft.
>
> --
>
> Did we reach a concensus on this?
>
> :-)
>
> Russ
>
> __________________________________
> riw@cisco.com CCIE <>< Grace Alone
>
> _______________________________________________
> RPSEC mailing list
> RPSEC@ietf.org
> https://www1.ietf.org/mailman/listinfo/rpsec


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



From exim@www1.ietf.org  Thu Jul 31 14:40:03 2003
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07736
	for <rpsec-archive@odin.ietf.org>; Thu, 31 Jul 2003 14:40:03 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIKv-0007yt-Lp
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 14:39:37 -0400
Received: (from exim@localhost)
	by www1.ietf.org (8.12.8/8.12.8/Submit) id h6VIdbp3030678
	for rpsec-archive@odin.ietf.org; Thu, 31 Jul 2003 14:39:37 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIKv-0007yj-J6
	for rpsec-web-archive@optimus.ietf.org; Thu, 31 Jul 2003 14:39:37 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07725
	for <rpsec-web-archive@ietf.org>; Thu, 31 Jul 2003 14:39:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIKs-0006TX-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 14:39:34 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIKs-0006TU-00
	for rpsec-web-archive@ietf.org; Thu, 31 Jul 2003 14:39:34 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIKL-0007v9-4D; Thu, 31 Jul 2003 14:39:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by optimus.ietf.org with esmtp (Exim 4.20)
	id 19iIKF-0007uy-JB
	for rpsec@optimus.ietf.org; Thu, 31 Jul 2003 14:38:55 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA07706
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:38:50 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIKC-0006Sz-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 14:38:52 -0400
Received: from sj-iport-1-in.cisco.com ([171.71.176.70] helo=sj-iport-1.cisco.com)
	by ietf-mx with esmtp (Exim 4.12)
	id 19iIKC-0006Sv-00
	for rpsec@ietf.org; Thu, 31 Jul 2003 14:38:52 -0400
Received: from cisco.com (uzura.cisco.com [64.102.17.77])
	by rtp-core-2.cisco.com (8.12.9/8.12.6) with ESMTP id h6VIcKxc005169
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:38:20 -0400 (EDT)
Received: from russpc.nc.rr.com (rtp-vpn1-3.cisco.com [10.82.224.3])
	by cisco.com (8.8.8/2.6/Cisco List Logging/8.8.8) with ESMTP id OAA29776
	for <rpsec@ietf.org>; Thu, 31 Jul 2003 14:38:19 -0400 (EDT)
Date: Thu, 31 Jul 2003 14:38:19 -0400 (Eastern Daylight Time)
From: Russ White <ruwhite@cisco.com>
Reply-To: Russ White <riw@cisco.com>
To: Routing Protocols Security Working Group <rpsec@ietf.org>
Subject: Re: [RPSEC] Section 3.1.1 Comments
In-Reply-To: <3F29600C.C53D2291@alcatel.com>
Message-ID: <Pine.WNT.4.55.0307311438050.2672@russpc>
References: <Pine.WNT.4.55.0307132311010.1416@russpc> <3F29600C.C53D2291@alcatel.com>
X-X-Sender: ruwhite@uzura.cisco.com
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: rpsec-admin@ietf.org
Errors-To: rpsec-admin@ietf.org
X-BeenThere: rpsec@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=unsubscribe>
List-Id: Routing Protocol Security Requirements  <rpsec.ietf.org>
List-Post: <mailto:rpsec@ietf.org>
List-Help: <mailto:rpsec-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/rpsec>,
	<mailto:rpsec-request@ietf.org?subject=subscribe>


I think we have concensus on this one?

:-)

Russ

On Thu, 31 Jul 2003, Alex Audu wrote:

> The recommended change is good.  I'd leave the MANET example in also
> since it doesn't hurt.
>
> Regards,
> Alex.
>
> Russ White wrote:
>
> > I think I originally asked this:
> >
> > Replace this:
> >
> >    neighbor. For example, in OSPF (that is, before the MD5 part was
> >    added), OSPF speaks to all routers on the local link that answer to
> >    the AllSPFRouters multicast address.  Furthermore, MANET protocols
> >    frequently speak over the broadcast link.
> >
> > with:
> >
> > For example, an OSPF router will form a peering relationship with any
> > attached device which appears to be running OSPF, unless MD5
> > authentication (or some other means) is used to prevent the peering
> > relationship from forming.
> >
> > I'd pull the manet example, one is enough here, and reference the OSPF
> > MD5 draft.
> >
> > --
> >
> > Did we reach a concensus on this?
> >
> > :-)
> >
> > Russ
> >
> > __________________________________
> > riw@cisco.com CCIE <>< Grace Alone
> >
> > _______________________________________________
> > RPSEC mailing list
> > RPSEC@ietf.org
> > https://www1.ietf.org/mailman/listinfo/rpsec
>

__________________________________
riw@cisco.com CCIE <>< Grace Alone


_______________________________________________
RPSEC mailing list
RPSEC@ietf.org
https://www1.ietf.org/mailman/listinfo/rpsec



