Re: WG status 2003/08/13
"Leech, Marcus (EXCHANGE:FITZ:8M86)" <[email protected]> Wed, 13 Aug 2003 15:24:14 -0400
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Nortel Networks |
| Message-ID | <[email protected]> |
Pekka Savola wrote: > > A few comments. > > On Wed, 13 Aug 2003, Leech, Marcus (EXCHANGE:FITZ:8M86) wrote: > > Such reason would consist of: > > o strong indication (and this is perhaps more important) that network operators > > would actually deploy it. > > We'd defininitely deploy it if: > > - it'd get implemented by our vendors, > - it would be simple enough to operate (read: current draft is too > complex; we'd want to run it without any crypto/certificate/XML parts > except the (weak) random number generator, a thing I tried to point out at > SF IETF56), and The really onerous crypto bits are OPTIONAL. I don't remember the details of your random-number proposal (some kind of out-of-band packet verifier?), but it sounds, on the surface, to be computationally about the same cost as the existing proposal (which only needs to trigger 1/N, N=large packets anyway). > > > o strong indication that this technology continues to be forensically useful, > > in the face of increasing adoption of ingress/egress filtering, and the > > use of so-called diffuse DDOS attack scenarios. > > This is a very good question, and I believe one of the most important ones > in this decision. > > I do not believe ingress/egress filtering adoption rate has risen > significantly, but more and more worm-based attacks seem to indicate that > the typical trend is not to attack by address spoofing from a few > sources and try to cover your tracks, but by brute force. > It would be useful to get the perspective of providers on this--if they aren't adopting ingress/egress filtering, why would they adopt itrace? -- ---------------------------------------------------------------------- Marcus Leech Mail: Advisor Phone: (ESN) 393-9145 +1 613 763 9145 Security Architecture and Planning Fax: (ESN) 393-2754 +1 613 763 2754 Nortel Networks [email protected] -----------------Expressed opinions are my own, not my employer's------