Re: WG status 2003/08/13

"Leech, Marcus (EXCHANGE:FITZ:8M86)" <[email protected]> Wed, 13 Aug 2003 15:24:14 -0400
Newsgroups gmane.ietf.itrace
Organization Nortel Networks
Message-ID <[email protected]>
Pekka Savola wrote:
> 
> A few comments.
> 
> On Wed, 13 Aug 2003, Leech, Marcus (EXCHANGE:FITZ:8M86) wrote:
> > Such reason would consist of:
> >   o strong indication (and this is perhaps more important) that network operators
> >     would actually deploy it.
> 
> We'd defininitely deploy it if:
> 
>  - it'd get implemented by our vendors,
>  - it would be simple enough to operate (read: current draft is too
> complex; we'd want to run it without any crypto/certificate/XML parts
> except the (weak) random number generator, a thing I tried to point out at
> SF IETF56), and

The really onerous crypto bits are OPTIONAL.  I don't remember the details
  of your random-number proposal (some kind of out-of-band packet verifier?),
  but it sounds, on the surface, to be computationally about the same cost
  as the existing proposal (which only needs to trigger 1/N, N=large packets
  anyway).

> 
> >   o strong indication that this technology continues to be forensically useful,
> >     in the face of increasing adoption of ingress/egress filtering, and the
> >     use of so-called diffuse DDOS attack scenarios.
> 
> This is a very good question, and I believe one of the most important ones
> in this decision.
> 
> I do not believe ingress/egress filtering adoption rate has risen
> significantly, but more and more worm-based attacks seem to indicate that
> the typical trend is not to attack by address spoofing from a few
> sources and try to cover your tracks, but by brute force.
>
It would be useful to get the perspective of providers on this--if they aren't
  adopting ingress/egress filtering, why would they adopt itrace?



-- 
----------------------------------------------------------------------
Marcus Leech                             Mail:
Advisor                                  Phone: (ESN) 393-9145  +1 613 763 9145
Security Architecture and Planning       Fax:   (ESN) 393-2754  +1 613 763 2754
Nortel Networks                          [email protected]
-----------------Expressed opinions are my own, not my employer's------