Re: [bmwg] Secdir early review of draft-ietf-bmwg-ngfw-performance-00

"MORTON, ALFRED C (AL)" <acm@research.att.com> Tue, 09 July 2019 07:07 UTC

Return-Path: <acm@research.att.com>
X-Original-To: bmwg@ietfa.amsl.com
Delivered-To: bmwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 113CC1202F8; Tue, 9 Jul 2019 00:07:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nnIIdapDPjb0; Tue, 9 Jul 2019 00:07:26 -0700 (PDT)
Received: from mx0a-00191d01.pphosted.com (mx0b-00191d01.pphosted.com [67.231.157.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1A141200F7; Tue, 9 Jul 2019 00:07:25 -0700 (PDT)
Received: from pps.filterd (m0049458.ppops.net [127.0.0.1]) by m0049458.ppops.net-00191d01. (8.16.0.27/8.16.0.27) with SMTP id x6975HXq016747; Tue, 9 Jul 2019 03:07:22 -0400
Received: from tlpd255.enaf.dadc.sbc.com (sbcsmtp3.sbc.com [144.160.112.28]) by m0049458.ppops.net-00191d01. with ESMTP id 2tmhqswg3q-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 09 Jul 2019 03:07:22 -0400
Received: from enaf.dadc.sbc.com (localhost [127.0.0.1]) by tlpd255.enaf.dadc.sbc.com (8.14.5/8.14.5) with ESMTP id x6977LtQ001959; Tue, 9 Jul 2019 02:07:21 -0500
Received: from zlp30495.vci.att.com (zlp30495.vci.att.com [135.46.181.158]) by tlpd255.enaf.dadc.sbc.com (8.14.5/8.14.5) with ESMTP id x6977JVi001918 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 9 Jul 2019 02:07:19 -0500
Received: from zlp30495.vci.att.com (zlp30495.vci.att.com [127.0.0.1]) by zlp30495.vci.att.com (Service) with ESMTP id B4836400A0A3; Tue, 9 Jul 2019 07:07:19 +0000 (GMT)
Received: from clpi183.sldc.sbc.com (unknown [135.41.1.46]) by zlp30495.vci.att.com (Service) with ESMTP id 974FB400A0A2; Tue, 9 Jul 2019 07:07:19 +0000 (GMT)
Received: from sldc.sbc.com (localhost [127.0.0.1]) by clpi183.sldc.sbc.com (8.14.5/8.14.5) with ESMTP id x6977Jc3009187; Tue, 9 Jul 2019 02:07:19 -0500
Received: from mail-green.research.att.com (mail-green.research.att.com [135.207.255.15]) by clpi183.sldc.sbc.com (8.14.5/8.14.5) with ESMTP id x69774l2008165; Tue, 9 Jul 2019 02:07:04 -0500
Received: from exchange.research.att.com (njbdcas1.research.att.com [135.197.255.61]) by mail-green.research.att.com (Postfix) with ESMTP id 9042DE1098; Tue, 9 Jul 2019 03:05:37 -0400 (EDT)
Received: from njmtexg5.research.att.com ([fe80::b09c:ff13:4487:78b6]) by njbdcas1.research.att.com ([fe80::8c6b:4b77:618f:9a01%11]) with mapi id 14.03.0439.000; Tue, 9 Jul 2019 03:06:17 -0400
From: "MORTON, ALFRED C (AL)" <acm@research.att.com>
To: Brian Monkman <bmonkman@netsecopen.org>, 'Kathleen Moriarty' <Kathleen.Moriarty.ietf@gmail.com>, "secdir@ietf.org" <secdir@ietf.org>
CC: "draft-ietf-bmwg-ngfw-performance.all@ietf.org" <draft-ietf-bmwg-ngfw-performance.all@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>, "bmwg@ietf.org" <bmwg@ietf.org>
Thread-Topic: Secdir early review of draft-ietf-bmwg-ngfw-performance-00
Thread-Index: AQHVNc0IhaR19GS8XU2P9JMA53XEoKbBci0AgABqNaA=
Date: Tue, 09 Jul 2019 07:06:16 +0000
Message-ID: <4D7F4AD313D3FC43A053B309F97543CFA0AA95B9@njmtexg5.research.att.com>
References: <156261828836.820.7530581707536369773@ietfa.amsl.com> <00b701d535cd$5dd9a490$198cedb0$@netsecopen.org>
In-Reply-To: <00b701d535cd$5dd9a490$198cedb0$@netsecopen.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [24.134.50.125]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-07-09_03:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_policy_notspam policy=outbound_policy score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1810050000 definitions=main-1907090085
Archived-At: <https://mailarchive.ietf.org/arch/msg/bmwg/1fVt7uu1ISQ0Rlq4Up1AwpNGLB0>
Subject: Re: [bmwg] Secdir early review of draft-ietf-bmwg-ngfw-performance-00
X-BeenThere: bmwg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Benchmarking Methodology Working Group <bmwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bmwg>, <mailto:bmwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bmwg/>
List-Post: <mailto:bmwg@ietf.org>
List-Help: <mailto:bmwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bmwg>, <mailto:bmwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jul 2019 07:07:28 -0000

Let me add my thanks for your review Kathleen!

@Brian and team, there is a "standard" security section
in wg chair's slides and other drafts. Please feel 
free to improve and customize the text for this 
case of next-gen firewall benchmarking 
(in isolated test environments, consistent with our charter).

regards,
Al
bmwg co-chair

> -----Original Message-----
> From: Brian Monkman [mailto:bmonkman@netsecopen.org]
> Sent: Monday, July 8, 2019 4:40 PM
> To: 'Kathleen Moriarty' <Kathleen.Moriarty.ietf@gmail.com>;
> secdir@ietf.org
> Cc: draft-ietf-bmwg-ngfw-performance.all@ietf.org; ietf@ietf.org;
> bmwg@ietf.org
> Subject: RE: Secdir early review of draft-ietf-bmwg-ngfw-performance-00
> 
> Thanks for your feedback Kathleen. I will review it with the team and may
> get back to you with questions.
> 
> Brian Monkman
> 
> -----Original Message-----
> From: Kathleen Moriarty via Datatracker <noreply@ietf.org>
> Sent: July 8, 2019 4:38 PM
> To: secdir@ietf.org
> Cc: draft-ietf-bmwg-ngfw-performance.all@ietf.org; ietf@ietf.org;
> bmwg@ietf.org
> Subject: Secdir early review of draft-ietf-bmwg-ngfw-performance-00
> 
> Reviewer: Kathleen Moriarty
> Review result: Has Nits
> 
> Thank you for your work on draft-ietf-bmwg-ngfw-performance.  This is a
> straightforward review establishing metrics for comparison of SUT/DUT for
> firewalls establishing measurement requirements as well as acceptance
> criteria.
>  When crypto is recommended for use in testing, it's current, although it
> should be noted that this is just for test environments.  In terms of
> security, I think this document is ready with nits.
> 
> Please add a security considerations section.  Feel free to include
> something like what's above.
> 
> Section 4.1: Nit
> 
> Spell out Device under test/system under test on first use.  I don't think
> it comes up that often in the IESG review cycle.  I had to look it up and
> my memory was jogged.
> 
> Sorry for my late 'early' review!
> 
>