Re: [77attendees] Bar BoF: ip traceback

Jari Arkko <jari.arkko@piuha.net> Thu, 25 March 2010 16:46 UTC

Return-Path: <jari.arkko@piuha.net>
X-Original-To: 77attendees@core3.amsl.com
Delivered-To: 77attendees@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 354C43A68D7 for <77attendees@core3.amsl.com>; Thu, 25 Mar 2010 09:46:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.653
X-Spam-Level:
X-Spam-Status: No, score=0.653 tagged_above=-999 required=5 tests=[AWL=0.664, BAYES_00=-2.599, DNS_FROM_OPENWHOIS=1.13, HTML_MESSAGE=0.001, MIME_HTML_ONLY=1.457]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 19Lu0FdGfA4H for <77attendees@core3.amsl.com>; Thu, 25 Mar 2010 09:46:27 -0700 (PDT)
Received: from p130.piuha.net (p130.piuha.net [IPv6:2001:14b8:400::130]) by core3.amsl.com (Postfix) with ESMTP id E01953A6CF8 for <77attendees@ietf.org>; Thu, 25 Mar 2010 09:46:20 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by p130.piuha.net (Postfix) with ESMTP id 790FE2CEC0; Thu, 25 Mar 2010 18:46:42 +0200 (EET)
X-Virus-Scanned: amavisd-new at piuha.net
Received: from p130.piuha.net ([127.0.0.1]) by localhost (p130.piuha.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Aq6BEdK3z5TK; Thu, 25 Mar 2010 18:46:41 +0200 (EET)
Received: from [IPv6:::1] (unknown [IPv6:2001:14b8:400::130]) by p130.piuha.net (Postfix) with ESMTP id CF7B02CD07; Thu, 25 Mar 2010 18:46:39 +0200 (EET)
Message-ID: <4BAB936E.6010307@piuha.net>
Date: Thu, 25 Mar 2010 09:46:38 -0700
From: Jari Arkko <jari.arkko@piuha.net>
User-Agent: Thunderbird 2.0.0.24 (X11/20100317)
MIME-Version: 1.0
To: Yoav Nir <ynir@checkpoint.com>
References: <4BA8BCE3.5020309@is.naist.jp> <4BA95B6A.5040707@is.naist.jp> <4BAB0464.2010307@is.naist.jp> <4BAB7A4D.7070904@piuha.net> <8133D17D-D9B6-40A6-AE9B-80BF90A5223D@checkpoint.com>
In-Reply-To: <8133D17D-D9B6-40A6-AE9B-80BF90A5223D@checkpoint.com>
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: "77attendees@ietf.org" <77attendees@ietf.org>
Subject: Re: [77attendees] Bar BoF: ip traceback
X-BeenThere: 77attendees@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: <77attendees.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/77attendees>, <mailto:77attendees-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/77attendees>
List-Post: <mailto:77attendees@ietf.org>
List-Help: <mailto:77attendees-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/77attendees>, <mailto:77attendees-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Mar 2010 16:46:33 -0000

Yoav,

Thanks for the report! Additional comments inline:

The just made the two presentations (traceback experiment and using this to identify BOTs based on their DNS requests). Both presentations are on the web page.

There were no ADs in the room. AFAIK no WG chairs either, which is somewhat a shame, so no conclusions either.
  

Yeah. Sorry for not being in the room. I wanted to be there, but already had multiple overlapping things on that timeslot... that being said, the lack of ADs or chairs should not prevent conclusions from being made :-)

My own, personal conclusion was that this was interesting and has potential. There *is* work to be done (two different versions that they wrote did not interoperate properly) and since success requires wide adoption by ISPs, I believe that the IETF is probably the right place for this.  But these are just my personal opinions, and I have no idea if we can get enough people to actually work on this.

I suggest that the correct next step is for the authors to contact one or more ADs. Though this seems directly related to security, the fact that this would be a protocol that would run between AS edge routers, it could fall to other areas as well. So I think the next step should be scheduling a BoF for next IETF, and making sure that the right people are there.
  

The question in my mind is: is the world interested in this technology. Previous IETF efforts in traceback failed IMO due to lack of operator/vendor interest. We should not create new efforts unless that interest surges again. Is it surging, and if so, why?

Jari

On Mar 25, 2010, at 7:59 AM, Jari Arkko wrote:

  
Are there minutes, or better yet, a conclusion?

Jari

Hiroaki Hazeyama kirjoitti:
    
We putted our presentation materials of the ip traceback bar bof on
https://www.telecom-isac.jp/tb/index_e.html" rel="nofollow">https://www.telecom-isac.jp/tb/index_e.html

Thanks,
H. Hazeyama

(2010/03/24 9:23), Hiroaki Hazeyama wrote:
      
the location of the ip traceback bar bof is Carmel.


thanks,
H. Hazeyama


(2010/03/23 22:06), Hiroaki Hazeyama wrote:
        
Hi,

We will have a IP traceback bar bof

Day: Wednesday March 24
Time: 11:45,
location: TBD

Welcome to come for a discussion and suggestions and comments are 
highly desired.


The agenda of our Bar BOF is as follows;

- introduction of the traceback architecture of the field trial in 
Japan
(10 min.)

http://www.ietf.org/internet-drafts/draft-hazeyama-traceback-field-trial-00.txt" rel="nofollow">http://www.ietf.org/internet-drafts/draft-hazeyama-traceback-field-trial-00.txt 


- evaluation results of the tracback field trial in Japan (10 min.)

- DNS log-based traceback (10 min.)


Best regards,

H. Hazeyama




_______________________________________________
77attendees mailing list
77attendees@ietf.org
https://www.ietf.org/mailman/listinfo/77attendees" rel="nofollow">https://www.ietf.org/mailman/listinfo/77attendees
          
_______________________________________________
77attendees mailing list
77attendees@ietf.org
https://www.ietf.org/mailman/listinfo/77attendees" rel="nofollow">https://www.ietf.org/mailman/listinfo/77attendees
        
_______________________________________________
77attendees mailing list
77attendees@ietf.org
https://www.ietf.org/mailman/listinfo/77attendees" rel="nofollow">https://www.ietf.org/mailman/listinfo/77attendees

      
_______________________________________________
77attendees mailing list
77attendees@ietf.org
https://www.ietf.org/mailman/listinfo/77attendees" rel="nofollow">https://www.ietf.org/mailman/listinfo/77attendees

Scanned by Check Point Total Security Gateway.