RE: RDDP Security - misc comments, 1-16
"Jim Pinkerton" <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <E6564B8F86852D46A4E98C485FB33B8F066C93FD@WIN-MSG-10.wingroup.windeploy.ntdev.microsoft.com> |
________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of Jim Pinkerton Sent: Wednesday, January 21, 2004 4:57 PM To: [email protected] Subject: [rddp] RDDP Security - misc comments, 1-16 Mike Krause has done a great job reviewing the doc and coming up with questions. Because there are quite a few questions/issues raised, I'm dividing them into multiple emails to help focus the discussion. This email handles questions which don't bring up organizational issues, through question 16. Organizational issues will be in a separate email. > (9) 4.3 Is 4.3 just a place holder? Not clear its relevance to the draft > as many system properties can be attacked but these are outside the scope > of RDMA itself. This was included at the direction of security folks - in general, all of the attacks described in the document fall into the category of system integrity. One thing that is not done in the document is to directly reference which categories the attacks fall into (integrity, stability, confidentiality). Alternatively, if folks don't see a lot of value in this section (i.e. what is being attacked is obvious), I could just delete the section. [<jim>] I'll just delete it. I chatted with Sara Bitan, my new co-author on security, and the reality is that the concepts are pretty obvious - and the rest of the document specifies the exact thing being attacked and its repercussions, without referring to these generic, high level concepts. And I don't think it adds to the paper to put a new sentence after each attack stating which high level concept the attack applies to. Jim