Re: [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt

<mohamed.boucadair@orange.com> Wed, 05 June 2019 14:35 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF9FF120120 for <dots@ietfa.amsl.com>; Wed, 5 Jun 2019 07:35:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8grYWoIZN90S for <dots@ietfa.amsl.com>; Wed, 5 Jun 2019 07:35:04 -0700 (PDT)
Received: from orange.com (mta239.mail.business.static.orange.com [80.12.66.39]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5A93120114 for <dots@ietf.org>; Wed, 5 Jun 2019 07:35:03 -0700 (PDT)
Received: from opfedar06.francetelecom.fr (unknown [xx.xx.xx.8]) by opfedar22.francetelecom.fr (ESMTP service) with ESMTP id 45Jrsx4TwHz30G1; Wed, 5 Jun 2019 16:35:01 +0200 (CEST)
Received: from Exchangemail-eme6.itn.ftgroup (unknown [xx.xx.13.95]) by opfedar06.francetelecom.fr (ESMTP service) with ESMTP id 45Jrsx3S1mz3wbN; Wed, 5 Jun 2019 16:35:01 +0200 (CEST)
Received: from OPEXCAUBMA2.corporate.adroot.infra.ftgroup ([fe80::e878:bd0:c89e:5b42]) by OPEXCAUBM24.corporate.adroot.infra.ftgroup ([fe80::b43f:9973:861e:42af%21]) with mapi id 14.03.0439.000; Wed, 5 Jun 2019 16:35:01 +0200
From: mohamed.boucadair@orange.com
To: MeiLing Chen <chenmeiling@chinamobile.com>, dots <dots@ietf.org>
Thread-Topic: Re: [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt
Thread-Index: AQHVG4fEc7mSG1W4oUm1g5vQUCN4xqaNH2Qw
Date: Wed, 05 Jun 2019 14:35:00 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B93302EA94F31@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
References: <155931366911.6594.15565562891968407220@ietfa.amsl.com>, <787AE7BB302AE849A7480A190F8B93302EA93180@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <201906051816214259937@chinamobile.com>
In-Reply-To: <201906051816214259937@chinamobile.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.114.13.247]
Content-Type: multipart/alternative; boundary="_000_787AE7BB302AE849A7480A190F8B93302EA94F31OPEXCAUBMA2corp_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/0zlvQPVkeGZSJOkkacn47hyvDZU>
Subject: Re: [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Jun 2019 14:35:06 -0000

Hi Meiling,

The call home relies on the base signal channel spec except some very few items such as:

·         (D)TLS client/server roles reversal

·         Specific heartbeat mechanism induced by the above role reversal.

Cheers,
Med

De : MeiLing Chen [mailto:chenmeiling@chinamobile.com]
Envoyé : mercredi 5 juin 2019 12:16
À : BOUCADAIR Mohamed TGI/OLN; dots
Objet : Re: Re: [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt

Hi Med,
I have a question of dots-signal-call-home,  is it  a special version of dots signal channel?

best wishes.
Meiling Chen.
From: mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>
Date: 2019-05-31 22:44
To: dots@ietf.org<mailto:dots@ietf.org>
Subject: Re: [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt
Hi all,

We updated the draft with the following main changes:
* Specify the heartbeat mechanism for call home. The in the base spec won't be valid.
* Clarify that preconfigured mitigations are not allowed for call home.

Please review.

Cheers,
Med

> -----Message d'origine-----
> De : Dots [mailto:dots-bounces@ietf.org] De la part de internet-
> drafts@ietf.org
> Envoyé : vendredi 31 mai 2019 16:41
> À : i-d-announce@ietf.org
> Cc : dots@ietf.org
> Objet : [Dots] I-D Action: draft-ietf-dots-signal-call-home-02.txt
>
>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the DDoS Open Threat Signaling WG of the
> IETF.
>
>         Title           : Distributed Denial-of-Service Open Threat
> Signaling (DOTS) Signal Channel Call Home
>         Authors         : Tirumaleswar Reddy
>                           Mohamed Boucadair
>                           Jon Shallow
> Filename        : draft-ietf-dots-signal-call-home-02.txt
> Pages           : 24
> Date            : 2019-05-31
>
> Abstract:
>    This document specifies the DOTS signal channel Call Home service,
>    which enables a DOTS server to initiate a secure connection to a DOTS
>    client, and to receive the attack traffic information from the DOTS
>    client.  The DOTS server in turn uses the attack traffic information
>    to identify the compromised devices launching the outgoing DDoS
>    attack and takes appropriate mitigation action(s).
>
>    The DOTS Call Home service is not specific to the home networks; the
>    solution targets any deployment which requires to block DDoS attack
>    traffic closer to the source(s) of a DDoS attack.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-dots-signal-call-home/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-dots-signal-call-home-02
> https://datatracker.ietf.org/doc/html/draft-ietf-dots-signal-call-home-02
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-dots-signal-call-home-02
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots

_______________________________________________
Dots mailing list
Dots@ietf.org
https://www.ietf.org/mailman/listinfo/dots