RE: AD comments on draft-ietf-rserpool-threats-08
<[email protected]> Wed, 17 Oct 2007 10:37:17 -0500
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <[email protected]> |
Attacks 2.1 to 2.5 are all potential denial of service attacks. Instead of pounding a PE server with a stream of bits to deny service, what one could do instead is corrupt the ENRP database. Then when a client queries ENRP server for a pool address, ENRP potentially serves up the IP address of a non-existant server or a server that the hacker has set up. The gain for the attacker is either denial of service or directing the user to a server controlled by them. Any attempt to intentionally corrupt the ENRP database was considered a threat and potential for attack by the security design team. I will add text to the draft which says this. The formatting will also be updated. -- Maureen Maureen Stillman Nokia Enterprise Solutions Mobile: (607)229-3358 -----Original Message----- From: ext Magnus Westerlund [mailto:[email protected]] Sent: Tuesday, October 16, 2007 12:38 PM To: [email protected] Subject: [Rserpool] AD comments on draft-ietf-rserpool-threats-08 Hi, A couple of comments on the threats text. 1. I am missing clear text on what the benefit would be for different attacks. Lets take a look at 2.1 to 2.5 which all deals with adding or removing PE to the ENRP database. The text is not fortcomming what benefit the attacker would have in succeeding with it. For example 2.3 is clearly desirable from two persepctives: a. DDoS, by adding a PE that is a target for DDoS attack for some popular high volume service the attacker can register a PE that a lot of PUs will try to connect to. b. Man in the middle or masqurade attack on the service provided by the real PEs. If a malicious user adds itself as a PE and handles the request he can learn a lot of service data. This was just an example, for most threats the effect should be expanded to show what this can be used for and why it is a really bad idea to do this without security. 2. This a bit more nit: Can you please provide some proper indentation of the text. It is very hard to read and it is hard to find the section headings and where each new property:value paragraph starts. Cheers Magnus Westerlund IETF Transport Area Director & TSVWG Chair ---------------------------------------------------------------------- Multimedia Technologies, Ericsson Research EAB/TVM/M ---------------------------------------------------------------------- Ericsson AB | Phone +46 8 4048287 Torshamsgatan 23 | Fax +46 8 7575550 S-164 80 Stockholm, Sweden | mailto: [email protected] ---------------------------------------------------------------------- _______________________________________________ rserpool mailing list [email protected] https://www1.ietf.org/mailman/listinfo/rserpool