[manet] Re: [secdir] Secdir early review of draft-ietf-m anet-dlep-traffic-classification-12

Don Fedyk <[email protected]>
Newsgroups gmane.ietf.manet
Message-ID <PH7PR14MB53683D0D8060DF3360DAA195BB202@PH7PR14MB5368.namprd14.prod.outlook.com>
Hi Shawn

I have taken editorship of this document to help address the comments and move it along. We have confired with the authors on these points.

We have addressed the issue raised by you and other commenters.
Specific Comments inline [Don]

Thank you for your comments.
Don

-----Original Message-----
From: Shawn M Emery <[email protected]>
Sent: Tuesday, August 13, 2024 4:35 PM
To: [email protected]
Cc: [email protected]; [email protected]
Subject: Re: [secdir] Secdir early review of draft-ietf-manet-dlep-traffic-classification-12


In addition to disclosing the DoS attack, I would suggest adding that the privacy and integrity of the protocol's messaging is also covered by specifying DLEP's TLS option.

[Don] Added:
Old:
   This document introduces finer grain flow identification mechanisms
   to DLEP.  These mechanisms expose vulnerabilities similar to existing
   DLEP messages, e.g., an injected message resizes a credit window to a
   value that results in a denial of service.  The security mechanisms
   documented in [RFC8175] an be applied equally to the mechanism defined in this
   document.
New:
   This document introduces finer grain flow identification mechanisms
   to DLEP.  These mechanisms expose vulnerabilities similar to existing
   DLEP messages.  For example, a malicious actor masquerading as a DLEP
   peer could inject a modified Traffic Flow Classification Data Item
   resulting in changes to class of service for affected flows.  The
   Layer 2 and transport layer security mechanisms documented in
   [RFC8175] can be applied equally to the mechanism defined in this
   document.
Shawn.
--
On 8/10/24 11:52 PM, Shawn Emery via Datatracker wrote:
> Reviewer: Shawn Emery
> Review result: Has Nits
>
> I have reviewed this document as part of the security directorate's
> ongoing effort to review all IETF documents being processed by the
> IESG. These comments were written primarily for the benefit of the
> security area directors. Document editors and WG chairs should treat
> these comments just like any other last call comments.
>
> This standards track draft specifies a protocol for identifying
> various link control messages utilized by the Dynamic Link Exchange Protocol (DLEP).
>
> The security considerations sections does exist and discloses that the
> protocol opens up vulnerabilities for DoS by modifying or injecting
> protocol messages (e.g., decrease the max window size to a
> unrealistically small value).  The mitigation of said vulnerabilities
> is deferred to RFC 8175's security considerations, which prescribes
> TLS for transport security and provides IEEE-802.1AE and IEEE-802.1X
> as examples to protect Layer 2 from injecting or altering messages.  I believe this to be an accurate assertion.
>
> General comments:
>
> In order to help me fully understand the concepts of this protocol I
> think it would be nice to have examples for DSCP and PCP Sub-Data Items.

[Don] We added a diagram and a sequence diagram for the exchange of the Credit Flow Control and Traffic classification in the Credit flow control draft. This draft is mean only to be the traffic classification data type.

>
> Editorial comments:
>
> s/DLPE/DLEP/
[Don] Done.
>
>
> _______________________________________________
> secdir mailing list -- [email protected] To unsubscribe send an email to
> [email protected]
> wiki: https://wiki.ietf.org/group/secdir/SecDirReview


_______________________________________________
manet mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.