[IPFIX] R: secdir review of draft-ietf-ipfix-flow-selection-tech

"Salvatore D'Antonio" <[email protected]>
Newsgroups gmane.ietf.ipfix
Message-ID <[email protected]>
Dear all, 

 

I missed Dan’s e-mail. I apologise for that.

 

I will address Dan’s comments  in the new version of the Draft.

 

Best regards,

 

Salvatore

 

 

 

Da: Benoit Claise [mailto:[email protected]] 
Inviato: lunedì 12 novembre 2012 17:51
A: [email protected]
Cc: [email protected]
Oggetto: Fwd: secdir review of draft-ietf-ipfix-flow-selection-tech

 

Dear authors,

Reading my old emails, I'm not sure that you took into account Dan's
feedback.
At the very minimum, you should give a reply

Regards, Benoit



-------- Original Message -------- 


Subject: 

secdir review of draft-ietf-ipfix-flow-selection-tech


Date: 

Tue, 10 Apr 2012 16:59:43 -0700 (PDT)


From: 

Dan Harkins  <mailto:[email protected]> <[email protected]>


To: 

[email protected], [email protected],
[email protected]

 

  Hello,
 
  I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the
IESG.  These comments were written primarily for the benefit of the
security area directors.  Document editors and WG chairs should treat
these comments just like any other last call comments.
 
  This draft describes techniques to select flows which are sets of
packets with some common characteristics. The authors have accurately
identified what constitutes an attack-- an adversary having the ability
to influence flow selection-- and the Security Considerations give
a couple examples of this. They seem fine.
 
  There is reference to a paper "[GoRe07]" which does not appear in the
References and seems to give advice that I think is wrong: use a strong
cryptographically strong random number generator to thwart an attack in
which parameters of time-based sampling are discovered to predict the
selection decision. This attack can be thwarted by using a value that
the adversary cannot predict (sort of like an IV for CBC mode) instead
of a cryptographically strong random number. That leaves the random
number pool to applications that really need it (like a key exchange
that does a Diffie-Hellman). I suggest removing the reference to the
un-referenced paper and mention a weaker requirement to thwart that
attack.
 
  regards,
 
  Dan.
 
 
 

 

 

  _____  

Nessun virus nel messaggio.
Controllato da AVG - www.avg.com
Versione: 2012.0.2221 / Database dei virus: 2441/5390 - Data di rilascio:
12/11/2012

_______________________________________________
IPFIX mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipfix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.