Return-Path: <kaname@nttv6.jp>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 27F06130FB1;
 Tue,  5 Mar 2019 00:00:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, 
 DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
 HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=nttv6.jp
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id pOF66HU5GLSk; Tue,  5 Mar 2019 00:00:46 -0800 (PST)
Received: from guri.nttv6.jp (guri.nttv6.jp [IPv6:2402:c800:ff06:136::140])
 by ietfa.amsl.com (Postfix) with ESMTP id B9333130FD1;
 Tue,  5 Mar 2019 00:00:42 -0800 (PST)
Received: from z.nttv6.jp (z.nttv6.jp [IPv6:2402:c800:ff06:6::f])
 by guri.nttv6.jp (NTTv6MTA) with ESMTP id 6B00625F6BE;
 Tue,  5 Mar 2019 17:00:40 +0900 (JST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nttv6.jp; s=20180820; 
 t=1551772840;
 h=from:from:sender:reply-to:subject:subject:date:date:
 message-id:message-id:to:to:cc:cc:mime-version:mime-version:
 content-type:content-type:content-transfer-encoding:
 in-reply-to:in-reply-to:references:references;
 bh=YSae3FkfDgi78hRhSjDPmkQs3oQaXNdigpkLpqkC6p0=;
 b=Ey69gFtuVgMmrFhuBHNv+e7uIuaFh/4pZh07jymUKFJxSTQk+6jqICj1v+fF2iPYtCXL01
 cCD0KOzLvemCGV9LPnqJvKJ/3W9SO9lPraeeRHNNHkwbxbJxSH4erRNtkdMNvxjmStpCq4
 5TWfCuIyUyywMYWwa6RPIxchwd68zL4=
Received: from macbook-pro-17.lv4.nttv6.jp (fujiko.nttv6.jp
 [IPv6:2402:c800:ff06:136::141])
 by z.nttv6.jp (NTTv6MTA) with ESMTP id 60E62759007;
 Tue,  5 Mar 2019 17:00:40 +0900 (JST)
To: "Xialiang (Frank, Network Standard & Patent Dept)"
 <frank.xialiang@huawei.com>,
 "draft-nishizuka-dots-signal-control-filtering.authors@ietf.org"
 <draft-nishizuka-dots-signal-control-filtering.authors@ietf.org>
Cc: "dots@ietf.org" <dots@ietf.org>
References: <C02846B1344F344EB4FAA6FA7AF481F12C9D756B@dggemm511-mbx.china.huawei.com>
From: kaname nishizuka <kaname@nttv6.jp>
Message-ID: <21e92c8d-8df0-576a-db08-3163c74bba59@nttv6.jp>
Date: Tue, 5 Mar 2019 17:00:44 +0900
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:60.0)
 Gecko/20100101 Thunderbird/60.5.1
MIME-Version: 1.0
In-Reply-To: <C02846B1344F344EB4FAA6FA7AF481F12C9D756B@dggemm511-mbx.china.huawei.com>
Content-Type: multipart/alternative;
 boundary="------------A41A41F03D1B21A77ECA8C41"
Content-Language: en-US
Authentication-Results: guri.nttv6.jp; spf=pass smtp.mailfrom=kaname@nttv6.jp
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/B1oqfSRnmZcck3tNXa_wtTEL_m0>
Subject: Re: [Dots] Hi, authors. 3 comments:
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\)
 technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>,
 <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>,
 <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Mar 2019 08:00:48 -0000

This is a multi-part message in MIME format.
--------------A41A41F03D1B21A77ECA8C41
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit

Hi Frank,


On 2019/03/05 15:26, Xialiang (Frank, Network Standard & Patent Dept) wrote:
>
> Hi authors,
>
> I have 3 general comments as below:
>
> 1.Can you clarify the DOTS server administrative domain a little bit? What is the goal we define it?
>
We'll clarify it and update the draft.

> 2.Will this document open a door to make signal channel to cover the functions of data channel more and more?
>
> 3.I can accept the situation of changing the accept-list to the “deactivate” status, but is it a common use case we need to change a deny-list to the “immediate” status?
>
Regarding with 2 and 3, I can add one usecase to the draft.
When a DOTS client noticed that a system in its domain is being attacked, it will try to ask for help to a DOTS server in its transit provider (or somewhere in upstream networks).
Sometimes it is hard to get any information from the DOTS server if the upstream is saturated by attack traffic.
It is good strategy to enable ACL(set by data-channel) immediately first via signal-channel. Especially if it is rate-limit ACL, it will make a room for further communication over signal-channel.
Then, it will send mitigation request to the DOTS server.
This kind of procedure is really used by manual operation. Combination of ACL-based filtering and mitigation appliance is cost effective.
The proposed draft (signal-control-filtering) enable automation of it.

regards,
Kaname


> Thanks!
>
> B.R.
>
> Frank
>


--------------A41A41F03D1B21A77ECA8C41
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Hi Frank,<br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 2019/03/05 15:26, Xialiang (Frank,
      Network Standard &amp; Patent Dept) wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:C02846B1344F344EB4FAA6FA7AF481F12C9D756B@dggemm511-mbx.china.huawei.com">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	text-indent:21.0pt;
	font-size:10.5pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1489978593;
	mso-list-type:hybrid;
	mso-list-template-ids:-636854064 -255042266 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:18.0pt;
	text-indent:-18.0pt;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-text:"%2\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:42.0pt;
	text-indent:-21.0pt;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:63.0pt;
	text-indent:-21.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:84.0pt;
	text-indent:-21.0pt;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-text:"%5\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:105.0pt;
	text-indent:-21.0pt;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:126.0pt;
	text-indent:-21.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:147.0pt;
	text-indent:-21.0pt;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-text:"%8\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:168.0pt;
	text-indent:-21.0pt;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	margin-left:189.0pt;
	text-indent:-21.0pt;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span lang="EN-US">Hi authors,<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">I have 3 general
            comments as below:<o:p></o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:18.0pt;text-indent:-18.0pt;mso-list:l0
          level1 lfo1">
          <!--[if !supportLists]--><span lang="EN-US"><span
              style="mso-list:Ignore">1.<span style="font:7.0pt
                &quot;Times New Roman&quot;">      
              </span></span></span><!--[endif]--><span lang="EN-US">Can
            you clarify the DOTS server administrative domain a little
            bit? What is the goal we define it?<o:p></o:p></span></p>
      </div>
    </blockquote>
    We'll clarify it and update the draft.<br>
    <br>
    <blockquote type="cite"
cite="mid:C02846B1344F344EB4FAA6FA7AF481F12C9D756B@dggemm511-mbx.china.huawei.com">
      <div class="WordSection1">
        <p class="MsoListParagraph"
          style="margin-left:18.0pt;text-indent:0cm"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:18.0pt;text-indent:-18.0pt;mso-list:l0
          level1 lfo1">
          <!--[if !supportLists]--><span lang="EN-US"><span
              style="mso-list:Ignore">2.<span style="font:7.0pt
                &quot;Times New Roman&quot;">      
              </span></span></span><!--[endif]--><span lang="EN-US">Will
            this document open a door to make signal channel to cover
            the functions of data channel more and more?<o:p></o:p></span></p>
        <p class="MsoListParagraph"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoListParagraph"
          style="margin-left:18.0pt;text-indent:-18.0pt;mso-list:l0
          level1 lfo1">
          <!--[if !supportLists]--><span lang="EN-US"><span
              style="mso-list:Ignore">3.<span style="font:7.0pt
                &quot;Times New Roman&quot;">      
              </span></span></span><!--[endif]--><span lang="EN-US">I
            can accept the situation of changing the accept-list to the
            “deactivate” status, but is it a common use case we need to
            change a deny-list to the “immediate” status?<o:p></o:p></span></p>
      </div>
    </blockquote>
    Regarding with 2 and 3, I can add one usecase to the draft.<br>
    When a DOTS client noticed that a system in its domain is being
    attacked, it will try to ask for help to a DOTS server in its
    transit provider (or somewhere in upstream networks).<br>
    Sometimes it is hard to get any information from the DOTS server if
    the upstream is saturated by attack traffic.<br>
    It is good strategy to enable ACL(set by data-channel) immediately
    first via signal-channel. Especially if it is rate-limit ACL, it
    will make a room for further communication over signal-channel.<br>
    Then, it will send mitigation request to the DOTS server.<br>
    This kind of procedure is really used by manual operation.
    Combination of ACL-based filtering and mitigation appliance is cost
    effective.<br>
    The proposed draft (signal-control-filtering) enable automation of
    it.<br>
    <br>
    regards,<br>
    Kaname<br>
    <br>
    <br>
    <blockquote type="cite"
cite="mid:C02846B1344F344EB4FAA6FA7AF481F12C9D756B@dggemm511-mbx.china.huawei.com">
      <div class="WordSection1">
        <p class="MsoListParagraph"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Thanks!<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">B.R.<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Frank<o:p></o:p></span></p>
      </div>
    </blockquote>
    <br>
  </body>
</html>

--------------A41A41F03D1B21A77ECA8C41--

