Re: [Dots] Opsdir last call review of draft-ietf-dots-requirements-16

"Konda, Tirumaleswar Reddy" <TirumaleswarReddy_Konda@McAfee.com> Mon, 26 November 2018 05:15 UTC

Return-Path: <TirumaleswarReddy_Konda@mcafee.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D48C130F06; Sun, 25 Nov 2018 21:15:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.76
X-Spam-Level:
X-Spam-Status: No, score=-5.76 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.46, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=mcafee.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TEN200sO7dXP; Sun, 25 Nov 2018 21:15:55 -0800 (PST)
Received: from DNVWSMAILOUT1.mcafee.com (dnvwsmailout1.mcafee.com [161.69.31.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8AC641271FF; Sun, 25 Nov 2018 21:15:54 -0800 (PST)
X-NAI-Header: Modified by McAfee Email Gateway (5500)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mcafee.com; s=s_mcafee; t=1543209371; h=From: To:CC:Subject:Thread-Topic:Thread-Index:Date: Message-ID:References:In-Reply-To:Accept-Language: Content-Language:X-MS-Has-Attach:X-MS-TNEF-Correlator: dlp-product:dlp-version:dlp-reaction:authentication-results: x-originating-ip:x-ms-publictraffictype:x-microsoft-exchange-diagnostics: x-ms-exchange-antispam-srfa-diagnostics:x-ms-office365-filtering-correlation-id: x-microsoft-antispam:x-ms-traffictypediagnostic: x-microsoft-antispam-prvs:x-ms-exchange-senderadcheck: x-exchange-antispam-report-cfa-test:x-forefront-prvs: x-forefront-antispam-report:received-spf:x-microsoft-antispam-message-info: spamdiagnosticoutput:spamdiagnosticmetadata: Content-Type:Content-Transfer-Encoding:MIME-Version: X-MS-Exchange-CrossTenant-Network-Message-Id: X-MS-Exchange-CrossTenant-originalarrivaltime: X-MS-Exchange-CrossTenant-fromentityheader: X-MS-Exchange-CrossTenant-id:X-MS-Exchange-Transport-CrossTenantHeadersStamped: X-OriginatorOrg:X-NAI-Spam-Flag:X-NAI-Spam-Level: X-NAI-Spam-Threshold:X-NAI-Spam-Score:X-NAI-Spam-Version; bh=6XmKGdEu8lwEZskXevB684axK4CKylg+JblsoB tabEM=; b=GygOnRYk3eiWaQiwbP6VaNEXktHUk/lyPH1Kagh/ 9VuXv4hse8v2dDm3a3J1J+lyqJUgMsM1Jm7Yp12a8NtImlYN2/ yq+Hei4Ek6uGArxNhs5FbQrWRQ1/jFikuSSe7jQVcHHCHOuAiD vwtBcvGkxDDSP9tzCvXEWm7ut8zpz4A=
Received: from DNVEXAPP1N05.corpzone.internalzone.com (unknown [10.44.48.89]) by DNVWSMAILOUT1.mcafee.com with smtp (TLS: TLSv1/SSLv3,256bits,ECDHE-RSA-AES256-SHA384) id 7a43_0543_7a198c9f_1e70_4e64_8059_5128d4d99fde; Sun, 25 Nov 2018 23:16:11 -0600
Received: from DNVEXUSR1N08.corpzone.internalzone.com (10.44.48.81) by DNVEXAPP1N05.corpzone.internalzone.com (10.44.48.89) with Microsoft SMTP Server (TLS) id 15.0.1347.2; Sun, 25 Nov 2018 22:15:52 -0700
Received: from DNVEXUSR1N08.corpzone.internalzone.com (10.44.48.81) by DNVEXUSR1N08.corpzone.internalzone.com (10.44.48.81) with Microsoft SMTP Server (TLS) id 15.0.1347.2; Sun, 25 Nov 2018 22:15:50 -0700
Received: from DNVO365EDGE1.corpzone.internalzone.com (10.44.176.66) by DNVEXUSR1N08.corpzone.internalzone.com (10.44.48.81) with Microsoft SMTP Server (TLS) id 15.0.1347.2 via Frontend Transport; Sun, 25 Nov 2018 22:15:50 -0700
Received: from NAM05-CO1-obe.outbound.protection.outlook.com (10.44.176.240) by edge.mcafee.com (10.44.176.66) with Microsoft SMTP Server (TLS) id 15.0.1347.2; Sun, 25 Nov 2018 22:15:50 -0700
Received: from BN6PR16MB1425.namprd16.prod.outlook.com (10.172.207.19) by BN6PR16MB0051.namprd16.prod.outlook.com (10.172.111.137) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1361.16; Mon, 26 Nov 2018 05:15:49 +0000
Received: from BN6PR16MB1425.namprd16.prod.outlook.com ([fe80::b8de:7bb:cfa3:22ee]) by BN6PR16MB1425.namprd16.prod.outlook.com ([fe80::b8de:7bb:cfa3:22ee%8]) with mapi id 15.20.1361.019; Mon, 26 Nov 2018 05:15:49 +0000
From: "Konda, Tirumaleswar Reddy" <TirumaleswarReddy_Konda@McAfee.com>
To: Scott Bradner <sob@sobco.com>, "ops-dir@ietf.org" <ops-dir@ietf.org>
CC: "draft-ietf-dots-requirements.all@ietf.org" <draft-ietf-dots-requirements.all@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: Opsdir last call review of draft-ietf-dots-requirements-16
Thread-Index: AQHUhDTmLjFc+/OIs0ic94QUvZHQf6Vf65Sg
Date: Mon, 26 Nov 2018 05:15:48 +0000
Message-ID: <BN6PR16MB1425E843797A597B75D14A38EAD70@BN6PR16MB1425.namprd16.prod.outlook.com>
References: <154309157569.4300.10419245253211850237@ietfa.amsl.com>
In-Reply-To: <154309157569.4300.10419245253211850237@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
dlp-product: dlpe-windows
dlp-version: 11.0.500.52
dlp-reaction: no-action
authentication-results: spf=none (sender IP is ) smtp.mailfrom=TirumaleswarReddy_Konda@McAfee.com;
x-originating-ip: [103.245.47.20]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; BN6PR16MB0051; 6:aDdAApmSbWCXCS0L+7R+W7+MGXsmIvaQZvn3HxM7q0xb5RiuQsmiyG6GLP320hP7kIhz4nrnKD8Vwc0IwY8gKPZkEeRZqAgg1gtxVgA8eWhNnrlGTpJzdoLDPk7bnJhOQiYNsGjDg0lGg7rhUR/i6xhF7c57ZO5GE5jZ7krixnVCt/xq7tx7iJl5CEJ4fHC26BudC3JyAc1jYEMHkquPcMXa1H94jcWkb1GG/16aLlBaIZLiVponKWQlLyRcfdAELOxevHMn+r9OSO/3dr1pXhEAoe69vgLIAkzaNXI63T/tF9jtUHehc4R6LSQbXh5bfazHS2hk93MO/Zw2keUYce8/2K2FrFKbyyjFrn2/8R9SxYlTbVt3EPwWHlm2DvJ15hAG1VtK9MNVkJqBcuZXoi6+W/CpwIZoVxvRY/9hH3wMYG/y7aWc37+LaE/ijnOm6mcD09UxiOPQ/IXI/5NMiw==; 5:luOiSSyfW7e6uDKpmPQVAmZsqixG97bMzrEfqQhi4jlcnb2TBlyUPOY1jagqaE2Z6ZqAoRF+NHb4r4y199lkVO1styMtObDmRAf2qQ7M/tOMmCp3BDoje9KXK/bMfySF1lGjYD3OZl6bhSJHS7BGOrR9mSLSL2HegFF/M2ugGFY=; 7:9Hl4ZCYWgOmbI7eLfxX7qNClK3rZOPZnxf+9KIvPnEfBm8HVL/9/3tUPvCbVBHkvkVi/Qz8uVVQJ/sgFlwdl7LZsQ2ntc1z90Atvg6gCYKI7zAMbacImeP2WMctLwWnHOHXw5sflU+MOKLpdlBJvtQ==
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: b45fc9ef-4ea5-42d8-46cc-08d6535e3a53
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390098)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600074)(711020)(2017052603328)(7153060)(7193020); SRVR:BN6PR16MB0051;
x-ms-traffictypediagnostic: BN6PR16MB0051:
x-microsoft-antispam-prvs: <BN6PR16MB0051DF3B5D51B80D55EC8508EAD70@BN6PR16MB0051.namprd16.prod.outlook.com>
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(3002001)(10201501046)(3231443)(944501410)(52105112)(93006095)(93001095)(148016)(149066)(150057)(6041310)(20161123562045)(20161123560045)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123558120)(201708071742011)(7699051)(76991095); SRVR:BN6PR16MB0051; BCL:0; PCL:0; RULEID:; SRVR:BN6PR16MB0051;
x-forefront-prvs: 086831DFB4
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(346002)(376002)(366004)(39850400004)(136003)(396003)(32952001)(51914003)(199004)(189003)(13464003)(80792005)(68736007)(99286004)(106356001)(102836004)(105586002)(53546011)(6506007)(97736004)(478600001)(7696005)(14454004)(72206003)(8676002)(81156014)(81166006)(4326008)(8936002)(76176011)(53936002)(446003)(256004)(2906002)(9686003)(2501003)(55016002)(14444005)(71200400001)(71190400001)(66066001)(54906003)(33656002)(86362001)(74316002)(110136005)(25786009)(305945005)(5024004)(5660300001)(229853002)(3846002)(6116002)(316002)(11346002)(486006)(476003)(6246003)(186003)(26005)(6436002)(7736002)(85282002); DIR:OUT; SFP:1101; SCL:1; SRVR:BN6PR16MB0051; H:BN6PR16MB1425.namprd16.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: McAfee.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: bImCPMQw+YN590AJb03rhgWi4yNrFrHbh/Yk1Q7OxxXAjjTb0cMZSkpo84PE1eRc8OC6vt835PPx9qci0nHDxKQRZPV0mSAjTTxtHBk6Il/Z1auNjHELb8MPyDHWHGo5OO1r/GostmYaQiBTAcL+K/aD9tklZTgJGErGB9eybkXh+WrdJtiWda/Fmjfd1H/9bDV1JvN4t54ea21XcUL/3/TV8ndqsNX+ZQLx1M38PjUwR6y0wqXhFGk3n+A0tA/l9yInu9SqcrzF90HRabRNl49wsVWvy4XD/U1ikNcZnx9rOpamTc8dIZv75T4gIybqlQ4JFjoraUtsbJ2uLnkkj2iRUjzy79KH9CSX6jB1Ouw=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: b45fc9ef-4ea5-42d8-46cc-08d6535e3a53
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Nov 2018 05:15:48.8770 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 4943e38c-6dd4-428c-886d-24932bc2d5de
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR16MB0051
X-OriginatorOrg: mcafee.com
X-NAI-Spam-Flag: NO
X-NAI-Spam-Level:
X-NAI-Spam-Threshold: 15
X-NAI-Spam-Score: 0.4
X-NAI-Spam-Version: 2.3.0.9418 : core <6425> : inlines <6970> : streams <1805356> : uri <2755782>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/8T6nq9_HeHdq8xomT5db_bB4OC8>
Subject: Re: [Dots] Opsdir last call review of draft-ietf-dots-requirements-16
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Nov 2018 05:15:57 -0000

Hi Scott,

Thanks for the review, Please see inline 

> -----Original Message-----
> From: Scott Bradner <sob@sobco.com>
> Sent: Sunday, November 25, 2018 2:03 AM
> To: ops-dir@ietf.org
> Cc: draft-ietf-dots-requirements.all@ietf.org; ietf@ietf.org; dots@ietf.org
> Subject: Opsdir last call review of draft-ietf-dots-requirements-16
> 
> This email originated from outside of the organization. Do not click links or
> open attachments unless you recognize the sender and know the content is safe.
> 
> Reviewer: Scott Bradner
> Review result: Has Nits
> 
> This is an OPS-DIR review of Distributed Denial of Service (DDoS) Open Threat
> Signaling Requirements (draft-ietf-dots-requirements)
> 
> This document lists requirements for a protocol to used between providers of
> DDOS mitigation services and users of such services, as such there can be no
> direct operational issues with the document.  I also did not find any indirect
> operational issues.
> 
> I think the document would benefit from the addition of a section before the
> requirements section that specifically describes the setup assumed by the
> document. The descriptions before there hint at a presumed setup but a new
> section that clearly states the setup would be helpful. (the setup appears to be
> one where all network traffic to and from a protected entity flows through a
> DDoS mitigation service provider.  The provider includes one or more DOTS
> servers.  The protected entity includes one or more DOTS clients that
> communicate with the DOTS servers)

The requirements drafts refers to the DOTS architecture draft that discusses the architectural relationships, components and concepts used in a DOTS deployment.

> 
> Requirement SIG-005 addresses channel redirection – maybe there needs to be
> a way that clients can move to a new server on their own if they lose hearbeat
> from the server they were using – that might include a way for a server to
> provide a list of alternative servers to the clients

We can update SIG-004 requirement to say the following:

The DOTS client may be provided with a list of DOTS servers.  If the DOTS client considers the signal channel is defunct due to the extended absence of 
DOTS server heartbeat, the DOTS client can establish  a new DOTS signal channel with the other DOTS servers in the list.

-Tiru

>