Re: AD comments on draft-ietf-rserpool-threats-08
Magnus Westerlund <[email protected]> Mon, 18 Feb 2008 16:34:03 +0100
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <[email protected]> |
The new draft looks good! Cheers Magnus [email protected] skrev: > Attacks 2.1 to 2.5 are all potential denial of service attacks. Instead > of pounding a PE server with a stream of bits to deny service, what one > could do instead is corrupt the ENRP database. Then when a client > queries ENRP server for a pool address, ENRP potentially serves up the > IP address of a non-existant server or a server that the hacker has set > up. The gain for the attacker is either denial of service or directing > the user to a server controlled by them. Any attempt to intentionally > corrupt the ENRP database was considered a threat and potential for > attack by the security design team. > > I will add text to the draft which says this. > > The formatting will also be updated. > > -- Maureen > Maureen Stillman > Nokia Enterprise Solutions > Mobile: (607)229-3358 > > -----Original Message----- > From: ext Magnus Westerlund [mailto:[email protected]] > Sent: Tuesday, October 16, 2007 12:38 PM > To: [email protected] > Subject: [Rserpool] AD comments on draft-ietf-rserpool-threats-08 > > Hi, > > A couple of comments on the threats text. > > 1. I am missing clear text on what the benefit would be for different > attacks. Lets take a look at 2.1 to 2.5 which all deals with adding or > removing PE to the ENRP database. The text is not fortcomming what > benefit the attacker would have in succeeding with it. For example 2.3 > is clearly desirable from two persepctives: > a. DDoS, by adding a PE that is a target for DDoS attack for some > popular high volume service the attacker can register a PE that a lot of > PUs will try to connect to. > b. Man in the middle or masqurade attack on the service provided by the > real PEs. If a malicious user adds itself as a PE and handles the > request he can learn a lot of service data. > > This was just an example, for most threats the effect should be expanded > to show what this can be used for and why it is a really bad idea to do > this without security. > > 2. This a bit more nit: Can you please provide some proper indentation > of the text. It is very hard to read and it is hard to find the section > headings and where each new property:value paragraph starts. > > Cheers > > Magnus Westerlund > > IETF Transport Area Director & TSVWG Chair > ---------------------------------------------------------------------- > Multimedia Technologies, Ericsson Research EAB/TVM/M > ---------------------------------------------------------------------- > Ericsson AB | Phone +46 8 4048287 > Torshamsgatan 23 | Fax +46 8 7575550 > S-164 80 Stockholm, Sweden | mailto: [email protected] > ---------------------------------------------------------------------- > > > _______________________________________________ > rserpool mailing list > [email protected] > https://www1.ietf.org/mailman/listinfo/rserpool > -- Magnus Westerlund IETF Transport Area Director & TSVWG Chair ---------------------------------------------------------------------- Multimedia Technologies, Ericsson Research EAB/TVM ---------------------------------------------------------------------- Ericsson AB | Phone +46 8 4048287 Torshamsgatan 23 | Fax +46 8 7575550 S-164 80 Stockholm, Sweden | mailto: [email protected] ----------------------------------------------------------------------