Re: requirements and the security considerations
Jouni Korhonen <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <[email protected]> |
On Jun 21, 2013, at 3:14 AM, h chan <[email protected]> wrote: > The comments from Byoung-Jo Kim to REQ6 and Section 6 in version 4 were the following: > There are too much text in the security REQ6 that are vague and too wide. > > And Section 6. Security considerations should say "none", 'cause that's usually the section that discusses security considerations related to the draft itself. Since this is a requirement draft, there is no such thing. > There is a separate requirement earlier to cover security issues due to DMM. In some recent requirements documents I have seen rather extensive Security Consideration sections. What I would assume to see here, is a generic discussion on the security considerations on distributed environment. That is not about requirements itself per se. - JOuni (as an individual.. too hot here to wear any hat etc :) > > REQ6: Security considerations > > DMM protocol solutions MUST consider security risks introduced > by DMM into the network. Examples of such risks to be > considered may include authentication and authorization mechanisms > that allow a mobile host/router to use the mobility > support provided by the DMM solution; redirecting traffic to > the wrong host when providing DMM support; signaling message > protection for authentication, integrity and confidentiality. > > Motivation: Various attacks such as impersonation, denial of > service, man-in-the-middle attacks, and so on, may become newly > possible or easier to mount due to the introduction of DMM. Proof > of possession of past and new IP addresses may be needed. > > H Anthony Chan > > > -----Original Message----- > From: [email protected] [mailto:[email protected]] On Behalf Of Jouni Korhonen > Sent: Tuesday, June 18, 2013 2:40 AM > To: [email protected] > Subject: [DMM] requirements and the security considerations > > <no co-chair cap/bowler> > > Folks, > > I have been reading Section 6 Security Considerations: > > It is necessary to provide sufficient defense against possible > security attacks, or to adopt existing security mechanisms and > protocols to provide sufficient security protections. For instance, > EAP-based authentication can be used for access network security, > while IPsec can be used for end-to-end security. > > I think this text still deserves some tweaking. First, "provide sufficient defense against possible security attacks".. against whom? > > Second, should the text say something that the DMM protocol itself must not be usable as a tool to launch an attack by a malicious mobile node that happens to know that it is attached to a network implementing DMM and knows (somehow) how the DMM protocol functions? > > - Jouni > _______________________________________________ > dmm mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dmm