[manet] Re: [secdir] Secdir early review of draft-ietf-m anet-dlep-traffic-classification-12
Shawn M Emery <[email protected]>
| Newsgroups | gmane.ietf.manet |
|---|---|
| Message-ID | <[email protected]> |
Hi Don, Comments begin with SME. On 11/19/24 2:10 PM, Don Fedyk wrote: > Hi Shawn > > I have taken editorship of this document to help address the comments and move it along. We have confired with the authors on these points. > > We have addressed the issue raised by you and other commenters. > Specific Comments inline [Don] > > Thank you for your comments. > Don > > -----Original Message----- > From: Shawn M Emery<[email protected]> > Sent: Tuesday, August 13, 2024 4:35 PM > To:[email protected] > Cc:[email protected];[email protected] > Subject: Re: [secdir] Secdir early review of draft-ietf-manet-dlep-traffic-classification-12 > > > In addition to disclosing the DoS attack, I would suggest adding that the privacy and integrity of the protocol's messaging is also covered by specifying DLEP's TLS option. > > [Don] Added: > Old: > This document introduces finer grain flow identification mechanisms > to DLEP. These mechanisms expose vulnerabilities similar to existing > DLEP messages, e.g., an injected message resizes a credit window to a > value that results in a denial of service. The security mechanisms > documented in [RFC8175] an be applied equally to the mechanism defined in this > document. > New: > This document introduces finer grain flow identification mechanisms > to DLEP. These mechanisms expose vulnerabilities similar to existing > DLEP messages. For example, a malicious actor masquerading as a DLEP > peer could inject a modified Traffic Flow Classification Data Item > resulting in changes to class of service for affected flows. The > Layer 2 and transport layer security mechanisms documented in > [RFC8175] can be applied equally to the mechanism defined in this > document. SME: I believe these updated references cover my concerns. > ... > On 8/10/24 11:52 PM, Shawn Emery via Datatracker wrote: >> Reviewer: Shawn Emery >> Review result: Has Nits >> >> I have reviewed this document as part of the security directorate's >> ongoing effort to review all IETF documents being processed by the >> IESG. These comments were written primarily for the benefit of the >> security area directors. Document editors and WG chairs should treat >> these comments just like any other last call comments. >> >> This standards track draft specifies a protocol for identifying >> various link control messages utilized by the Dynamic Link Exchange Protocol (DLEP). >> >> The security considerations sections does exist and discloses that the >> protocol opens up vulnerabilities for DoS by modifying or injecting >> protocol messages (e.g., decrease the max window size to a >> unrealistically small value). The mitigation of said vulnerabilities >> is deferred to RFC 8175's security considerations, which prescribes >> TLS for transport security and provides IEEE-802.1AE and IEEE-802.1X >> as examples to protect Layer 2 from injecting or altering messages. I believe this to be an accurate assertion. >> >> General comments: >> >> In order to help me fully understand the concepts of this protocol I >> think it would be nice to have examples for DSCP and PCP Sub-Data Items. > [Don] We added a diagram and a sequence diagram for the exchange of the Credit Flow Control and Traffic classification in the Credit flow control draft. This draft is mean only to be the traffic classification data type. SME: I see that now, thank you for the reference. >> Editorial comments: >> >> s/DLPE/DLEP/ > [Don] Done. SME: Thank you for the update. Regards, Shawn. -- _______________________________________________ manet mailing list -- [email protected] To unsubscribe send an email to [email protected]