minutes of cdi threat model call 08-16 monday
"Abbie Barbir" <[email protected]> Tue, 20 Aug 2002 14:06:22 -0400
| Newsgroups | gmane.ietf.cdi |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C24874.4AE6C880 Content-Type: text/plain; charset="iso-8859-1" hi all, here are the minutes of the call. Due to conflict in time, some people were not able to call. regards abbie Call on Monday 8/16/2002. Below are notes for the call. Issues and/or questions on which input from the larger CDI group is sought is indicated with "Q:". But of course any other input would be usefull. Callers: Abbie Barbir Oscar Batuner Kobus van der Merwe About scope of this work: Is limited to developing a threat model for CDI (not providing solutions). Q: Is the threat model limited to CDI or should we also cover theats related to CDNs in general? Might be difficult to understand the additional threats posed by CDI without understanding the threat model for CDNs. Things specifically considered out of scope: - Gaurantees regarding content integrity in case of content transformations in the network. - The security of CDN such as surrogates (i.e. can not improve on the security of the original system) Threats fall in two categories namely, network level threats and content level threats. Within both of these the distinction can be made between threats from outsiders (parties not taking part in the content peering arrangement) and from insiders (those taking part in content peering). This breakdown covers both intentional threats (i.e. malicious attacks) as well as unintentional threats (i.e. those due to system malfunction, programming error, configuration error etc). Threats from outsiders can be mitigated by using strong authentication and encryption. Q: Is this sufficient protection? Q: Do we want to make strong authentication and encryption a requirement? Q: Is both IPSec and TLS appropriate/scalable? Q: Should we (at this point) decide/debate above point? Threats from insiders are harder to deal with because of the trust relationship required for content internetworking. - Treatment of malformed messages: following the BGP model it is suggested that receival of a malformed message result in termination of peering relationship with the gateway involved. Malformed message could be as result of gateway being compromised, buggy implementation etc. Since it is impossible to tell the difference terminating this peer-to-peer relationship appears to be the only safe way to handle this. --- point the difference between "termination of peering relationship with the gateway involved" and terminating peer-to-peer relationship with the CDN involved. - A peer can always (intentionally or unintentionally) send incorrect advertisements which might lead to incorrect selections being made. E.g. a CDN might incorrectly advertise low load, low cost and good coverage and therefore attract a large proportion of traffic. This problem can be somewhat mitigated through filtering of advertisements and local policies but ultimately comes down to a trust relationship between peers. Migration of policy (might be generic CDN issue not CDI): If there is a certain trust relationship between content provider and consumer this relationship should be maintained when content is distributed via a CDN. (example from CDI arch draft). - This relationship should also be preserved when content moves between peering CDNs (policy migration). Authoritative: Q: Do we need a mechanism to allow a CDN to prove that it is authoritative to distribute content? Q: What does it mean to be authorized to distribute content? Things discussed somewhat outside the scope of threat model: - Might be a need for monitoring capability to allow some verification of the real time performance of a particular CDN - Was suggested that multiple gateways could be used to improve the robustness of the system --- Multiple gateways and monitoring are just a suggested solutions. This document should point to the underlying threats: - as the trust relationship is static by nature it can not be relied upon in dynamitic threats situations (attack, local malfunctioning or overloading). Usually CDN has a specific (proprietary) methods to deal with this problem, CDI has to provide protection at the internetworking level; - peering agreements may be vital for CDN functionality. This makes peering reliability a security issue: easy disintegration caused by attack on (or malfunctioning of) a single point of failure may result in global DoS. ------_=_NextPart_001_01C24874.4AE6C880 Content-Type: text/html; charset="iso-8859-1" <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2655.35"> <TITLE>minutes of cdi threat model call 08-16 monday</TITLE> </HEAD> <BODY> <BR> <P><FONT SIZE=2>hi all,</FONT> </P> <P><FONT SIZE=2>here are the minutes of the call.</FONT> <BR><FONT SIZE=2>Due to conflict in time, some people were not able to call.</FONT> </P> <P><FONT SIZE=2>regards</FONT> <BR><FONT SIZE=2>abbie</FONT> </P> <BR> <P><FONT SIZE=2>Call on Monday 8/16/2002. Below are notes for the call.</FONT> <BR><FONT SIZE=2>Issues and/or questions on which input from the larger</FONT> <BR><FONT SIZE=2>CDI group is sought is indicated with "Q:". But of course</FONT> <BR><FONT SIZE=2>any other input would be usefull.</FONT> </P> <P><FONT SIZE=2>Callers:</FONT> <BR><FONT SIZE=2>Abbie Barbir</FONT> <BR><FONT SIZE=2>Oscar Batuner</FONT> <BR><FONT SIZE=2>Kobus van der Merwe</FONT> </P> <P><FONT SIZE=2>About scope of this work:</FONT> <BR><FONT SIZE=2>Is limited to developing a threat model for CDI</FONT> <BR><FONT SIZE=2>(not providing solutions).</FONT> <BR><FONT SIZE=2>Q: Is the threat model limited to CDI or should we</FONT> <BR><FONT SIZE=2>also cover theats related to CDNs in general?</FONT> <BR><FONT SIZE=2>Might be difficult to understand the additional</FONT> <BR><FONT SIZE=2>threats posed by CDI without understanding</FONT> <BR><FONT SIZE=2>the threat model for CDNs.</FONT> </P> <P><FONT SIZE=2>Things specifically considered out of scope:</FONT> <BR><FONT SIZE=2>- Gaurantees regarding content integrity in case</FONT> <BR><FONT SIZE=2>of content transformations in the network.</FONT> <BR><FONT SIZE=2>- The security of CDN such as surrogates (i.e. can not improve</FONT> <BR><FONT SIZE=2>on the security of the original system)</FONT> </P> <P><FONT SIZE=2>Threats fall in two categories namely,</FONT> <BR><FONT SIZE=2>network level threats and content level threats.</FONT> <BR><FONT SIZE=2>Within both of these the distinction can be made between</FONT> <BR><FONT SIZE=2>threats from outsiders (parties not taking part</FONT> <BR><FONT SIZE=2>in the content peering arrangement) and from insiders</FONT> <BR><FONT SIZE=2>(those taking part in content peering).</FONT> <BR><FONT SIZE=2>This breakdown covers both intentional threats (i.e.</FONT> <BR><FONT SIZE=2>malicious attacks) as well as unintentional threats</FONT> <BR><FONT SIZE=2>(i.e. those due to system malfunction, programming error,</FONT> <BR><FONT SIZE=2>configuration error etc).</FONT> </P> <P><FONT SIZE=2>Threats from outsiders can be mitigated by using strong</FONT> <BR><FONT SIZE=2>authentication and encryption.</FONT> <BR><FONT SIZE=2>Q: Is this sufficient protection?</FONT> <BR><FONT SIZE=2>Q: Do we want to make strong authentication and encryption</FONT> <BR><FONT SIZE=2>a requirement?</FONT> <BR><FONT SIZE=2>Q: Is both IPSec and TLS appropriate/scalable?</FONT> <BR><FONT SIZE=2>Q: Should we (at this point) decide/debate above point?</FONT> </P> <P><FONT SIZE=2>Threats from insiders are harder to deal with because</FONT> <BR><FONT SIZE=2>of the trust relationship required for content internetworking.</FONT> </P> <P><FONT SIZE=2>- Treatment of malformed messages: following the BGP model</FONT> <BR><FONT SIZE=2>it is suggested that receival of a malformed message result</FONT> <BR><FONT SIZE=2>in termination of peering relationship with the gateway</FONT> <BR><FONT SIZE=2>involved. Malformed message could be as result of gateway</FONT> <BR><FONT SIZE=2>being compromised, buggy implementation etc. Since it is</FONT> <BR><FONT SIZE=2>impossible to tell the difference terminating this peer-to-peer</FONT> <BR><FONT SIZE=2>relationship appears to be the only safe way to handle this.</FONT> </P> <P><FONT SIZE=2>--- point the difference between "termination of </FONT> <BR><FONT SIZE=2>peering relationship with the gateway involved" and terminating </FONT> <BR><FONT SIZE=2>peer-to-peer relationship with the CDN involved.</FONT> </P> <P><FONT SIZE=2>- A peer can always (intentionally or unintentionally)</FONT> <BR><FONT SIZE=2>send incorrect advertisements which might lead to incorrect</FONT> <BR><FONT SIZE=2>selections being made. E.g. a CDN might incorrectly advertise low load,</FONT> <BR><FONT SIZE=2>low cost and good coverage and therefore attract a large</FONT> <BR><FONT SIZE=2>proportion of traffic. This problem can be somewhat mitigated</FONT> <BR><FONT SIZE=2>through filtering of advertisements and local policies but</FONT> <BR><FONT SIZE=2>ultimately comes down to a trust relationship between</FONT> <BR><FONT SIZE=2>peers.</FONT> </P> <P><FONT SIZE=2>Migration of policy (might be generic CDN issue not CDI):</FONT> <BR><FONT SIZE=2>If there is a certain trust relationship between content</FONT> <BR><FONT SIZE=2>provider and consumer this relationship should be maintained</FONT> <BR><FONT SIZE=2>when content is distributed via a CDN. (example from CDI arch</FONT> <BR><FONT SIZE=2>draft).</FONT> <BR><FONT SIZE=2> - This relationship should also be preserved when content moves </FONT> <BR><FONT SIZE=2>between peering CDNs (policy migration).</FONT> </P> <P><FONT SIZE=2>Authoritative:</FONT> <BR><FONT SIZE=2>Q: Do we need a mechanism to allow a CDN to prove that it</FONT> <BR><FONT SIZE=2>is authoritative to distribute content?</FONT> </P> <P><FONT SIZE=2>Q: What does it mean to be authorized to distribute content?</FONT> </P> <P><FONT SIZE=2>Things discussed somewhat outside the scope of threat model:</FONT> <BR><FONT SIZE=2>- Might be a need for monitoring capability to allow some</FONT> <BR><FONT SIZE=2>verification of the real time performance of a particular</FONT> <BR><FONT SIZE=2>CDN</FONT> <BR><FONT SIZE=2>- Was suggested that multiple gateways could be used to improve</FONT> <BR><FONT SIZE=2>the robustness of the system</FONT> <BR><FONT SIZE=2> --- Multiple gateways and monitoring are just a suggested </FONT> <BR><FONT SIZE=2>solutions. This document should point to the underlying threats:</FONT> </P> <P><FONT SIZE=2>- as the trust relationship is static by nature it can not be </FONT> <BR><FONT SIZE=2>relied upon in dynamitic threats situations (attack, local </FONT> <BR><FONT SIZE=2>malfunctioning or overloading). Usually CDN has a specific </FONT> <BR><FONT SIZE=2>(proprietary) methods to deal with this problem, CDI has to </FONT> <BR><FONT SIZE=2>provide protection at the internetworking level;</FONT> </P> <P><FONT SIZE=2>- peering agreements may be vital for CDN functionality. This makes </FONT> <BR><FONT SIZE=2>peering reliability a security issue: easy disintegration caused by </FONT> <BR><FONT SIZE=2>attack on (or malfunctioning of) a single point of failure may </FONT> <BR><FONT SIZE=2>result in global DoS. </FONT> </P> </BODY> </HTML> ------_=_NextPart_001_01C24874.4AE6C880--