RE: New WG Last Call on the Threats Assessment

[email protected]
Newsgroups gmane.ietf.rserpool
Message-ID <57A26D272F67A743952F6B4371B8F811021CFEDF@daebe007.americas.nokia.com>
Thanks for the comments on the threat document.

I agree we should mention this threat in the threat document.  I'll add it.

Concerning how to respond to the threat, I have 3 suggestions:

1) Take care of it in ASAP in the client.  ASAP will prevent the flooding of
the ENRP server with endpoint unreachable messages by some mechanism that
needs to be defined.
2) Take care of it in ENRP.  I believe that this is already done.  ENRP does
not automatically take the unreachable message as a mandate to delete the PE
from the database.
3) Do both 1 and 2.

I'm not convinced that the right response is to require all PUs to be
authenticated.  I think ASAP should handle this and protect the ENRP
servers.  ENRP should also protect itself and be suspicious of any message
from the PU as already specified.

Comments?

-- maureen

-----Original Message-----
From: ext Manuel Urueña [mailto:[email protected]]
Sent: Thursday, September 04, 2003 12:47 PM
To: [email protected]
Cc: Ong, Lyndon
Subject: Re: [Rserpool] New WG Last Call on the Threats Assessment


Hi,

Reviewing the threats document and the rest of the Rserpool info, I
think I have found one question not covered by the threats draft and I
don't know if it has been already discussed. The question is: What's the
trust relationship between PUs and ENRP servers? 

This is answered partially in the Threats draft in the 2.7 Requirement:
"ASAP needs to authenticate the ENRP server", but not in the other way.

There is one scenario where the ENRP server needs to trust a PU. Section
4.7 of ENRP draft explains how a PU tells a ENRP server that a PE is
unreachable. When an ENRP server receives a ENDPOINT_UNREACHABLE
message, "...MUST inmediately send a point-to-point ENDPOINT_KEEP_ALIVE
message to the PE in question." If many PUs send such messages, this may
lead to a DoS to the ENRP-PE connection.

This doesn't seem to be a very dangerous attack as KEEP_ALIVE messages
are small, but maybe could be documented so an ENRP server only sends
KEEP_ALIVE messages at certain rate. However, If I have understood
correctly, there is a problem related to the MAX-BAD-PE-REPORT counter.

An ENRP server SHOULD delete a PE from a pool even if it responds to
ENDPOINT_KEEP_ALIVE messages just because several ENDPOINT_UNREACHABLE
messages have been received. A rogue PU may just ask for all the PEs of
a pool and then send MAX-BAD-PE-REPORT+1 ENDPOINT_UNREACHABLE messages
for each PE to knock down the whole pool. Do I miss something?

Of course, if all PUs are trusted these attacks will never occur, but
IMHO that severely limits the number of PUs able to access to a pool.

Thanks,
--Manuel

> Hi Folks,
> 
> Maureen and I would like to start WG Last Call on the new version of the threats
> assessment (http://ietf.org/internet-drafts/draft-ietf-rserpool-threats-01.txt) that has
> now been posted on the server.  This would address comments on the architecture
> draft that a security section is needed - the security section would then reference
> the threats assessment for detailed discussion of security considerations.
> 
> Last Call will start today and and end on Monday, September 8th (I know it's over 
> Labor Day weekend, but it's not a long document).
> 
> Cheers,
> 
> L. Ong

-- 
Manuel Uruen~a - Universidad Carlos III de Madrid
GPG FP: 9BE9 9FFF ACFF 2887 80E6 50FE FABC A79F 5535 5A75
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.