Re: [Dots] Signal / Data / Alias / Filter Implementation

"Roland Dobbins" <rdobbins@arbor.net> Thu, 03 August 2017 08:04 UTC

Return-Path: <rdobbins@arbor.net>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DB9A2132323 for <dots@ietfa.amsl.com>; Thu, 3 Aug 2017 01:04:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.702
X-Spam-Level:
X-Spam-Status: No, score=-4.702 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=thescout.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QR_TBfjjE8B5 for <dots@ietfa.amsl.com>; Thu, 3 Aug 2017 01:04:52 -0700 (PDT)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0111.outbound.protection.outlook.com [104.47.34.111]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 63733126CB6 for <dots@ietf.org>; Thu, 3 Aug 2017 01:04:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=thescout.onmicrosoft.com; s=selector1-arbor-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=aAJnxr8XqRtNLNSjdlv/lS4pQKnXa31kAdSFk66ax4c=; b=HHM9l4Zn5euRa5YsldfT4+C8T4+sMSftOfGPwLVrkB9VbKSpekmIx8StraynWU1Nan8WWY5pK6t2W0xHtAOvyF8f3q8yTHyHJ2YwNYIvVSHP/Tw2smBQsA/mySYd5fdXyC7hZEDu6hZajGkruif+UQKAZDP5wzVqflpU6nJICXo=
Received: from [172.19.254.107] (49.228.111.8) by DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1304.22; Thu, 3 Aug 2017 08:04:49 +0000
From: Roland Dobbins <rdobbins@arbor.net>
To: Jon Shallow <supjps-ietf@jpshallow.com>
Cc: dots@ietf.org
Date: Thu, 03 Aug 2017 15:04:32 +0700
Message-ID: <78660E60-0A94-4164-A8C0-5485816DE059@arbor.net>
In-Reply-To: <040101d30c2e$14440f70$3ccc2e50$@jpshallow.com>
References: <035401d30b77$fb3a1da0$f1ae58e0$@jpshallow.com> <628E4313-95D3-42F5-9DDB-00C7B4EBB4D6@arbor.net> <039001d30ba3$7f4290c0$7dc7b240$@jpshallow.com> <B8BBF80E-5A5B-473D-A0B2-B6EFEC21DEBF@arbor.net> <4a158137-5c92-974e-3e4d-6c46fb3e5a52@nttv6.jp> <040101d30c2e$14440f70$3ccc2e50$@jpshallow.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.6r5347)
X-Originating-IP: [49.228.111.8]
X-ClientProxiedBy: HK2PR02CA0181.apcprd02.prod.outlook.com (2603:1096:201:21::17) To DM2PR0101MB1039.prod.exchangelabs.com (2a01:111:e400:3c19::28)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: bc86527a-b159-4a1c-2814-08d4da465127
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254152)(300000503095)(300135400095)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR0101MB1039;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 3:zNcuY6ZousOsx/6/zdjrMUK+aSNa7MQ7t2ZduBhmUIPnB4afoQjUtFiri8PogNIeiYygif1tsfcoO/CrvxLJhvZoDCDHzXFF/wG8n10tzKO+GMlSkk4hFlAh142tXxKqf1BQDUxuwI3h106QeQMEkWk6ZFZ7l2iYE7u+fKCoj87DFikfNumOFA8SbtOdOn4sdYRCMFr3ALnubReHYpkZ8TAlVbD9lNqHQV4mcyxnNq1IGE1Gt5xQ/IvFItBKHKWc; 25:GXS+Og1Q86uB/yZQtXxfasw5pQHCkSuc9SBedkwm3x0Emex/LEyWZnbGH8EgFHR5ao/doRe0H1KnwKbVI0ZxOigxz19uA/Rzwd6nhVumVf6wb59177317b92eTQAXy1gpPUuC68P0/f6zgIyQaKc9y49SGLpOQYWcTNzpsxfYX77fisyEZ+355vTDAxCayE+aMwwXmbmO3h/uscTOA2hKGwK7yS7etHBPiC1Br2q5N8Ncr9Zkj+08l2vSIuqt6jmdn6VrF9IfbNqcvvASYa5DCdZvAvVUDihs9nNs4IVAYkaJURihyYcspoxszINKE1gdwydgbUcGZLlx1jvNoPlOQ==; 31:toNkn8LYCagjfGVmthP7X6jaYBSeteZ4pSbhPxjmAYyckZJr6T4otLDib847Bfbd3qxKcvwR8qCYhcEFc9p7Boh2jTrUernJvf1suEviElAS96mBGfl849Yv8GAdIcGfmOfp6WyZ0S2Nqts4tmhkYEai5JbDTwvrMlcSBI0s+yeEtxeNzT1SWYFqVN0DOnfKe72IAnNfBecrTyyU1/Q7siJdk6P7Cki5QWKMiYvb00w=
X-MS-TrafficTypeDiagnostic: DM2PR0101MB1039:
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=rdobbins@arbor.net;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 20:kjkPRq8Q/xbBoVvSO2vj0Fh+qN1lEScb7eo5pDxZ+hdaOj6MMgwVPrXPzxw6oijllycJlnbtGH3SGSpBqyS0+rpTIyy/rCfutNemkQimayWmWLA3vRMa90hjXofZYX2i3pKwidpQYX+fFdCrPnUCxwYd9Ca8hD/fYwNyuEmQ1C+UmWV/t1sm6N00mG6OzDFw6rmIi3uJatB+yK+ZyZyQAiZ3NG9m5CXZKtvjVtneS1vhm1piPUe8f4Y4jl9wA/xM9QyLBsPA9WWV/+BSqeQahEQ/u5Act3Lnl+82+f5Ib6TFGMz0J5Go+qoixtjTntGLGTh2dpvP/vIIP8oPV2I891s67mtunAiQMsRlejQjMtpmLy/dqtQS5jA9cUS5maTlJBEGjohAt/BqW1OPl5DInu//AUA5cg2XnRV4foA2DJG3TiI6KOcByMUFmlonrlAy1h9X37Ec6s762fOy7SXcTAwnYggoD3f+KSTanL8ENAmQGXqbLu9rF4JKJQfN1LML; 4:KXH5KnEi47cVRyacEVAtzj9z3213oYs4Te0DaivkMF7k4Lc9jROKMhV09K07Wrkt1Qof2rzW0u6cgMY69oRNLWtQG/SLt/We33/fU+Tb0hWTUgk6S5oDQcHLFH3DlRyd+9rFXoEo8s+gkxZOnizFIc0mrbTQEj1IMPOb0yXBQpMfEYCN/xCrtGtPLirmTx5fxs0nYvUf5hgSP/LqpB0jlnoRg9ZR+scAcdhfc701hBkzgvE/Ur3Q3TPFmMtdvczD
X-Exchange-Antispam-Report-Test: UriScan:;
X-Microsoft-Antispam-PRVS: <DM2PR0101MB10397FA7E99E671E6C5C7F6FCAB10@DM2PR0101MB1039.prod.exchangelabs.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6041248)(20161123564025)(20161123560025)(20161123562025)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR0101MB1039; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR0101MB1039;
X-Forefront-PRVS: 03883BD916
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(7370300001)(4630300001)(6009001)(6049001)(39450400003)(39410400002)(39830400002)(39400400002)(199003)(24454002)(189002)(53546010)(93886004)(68736007)(38730400002)(97736004)(6246003)(50466002)(42186005)(5003940100001)(7350300001)(86362001)(106356001)(105586002)(36756003)(83716003)(82746002)(110136004)(6116002)(66066001)(3846002)(25786009)(76176999)(478600001)(50986999)(53936002)(50226002)(101416001)(47776003)(2950100002)(81166006)(189998001)(2906002)(6916009)(6666003)(81156014)(4326008)(8676002)(33656002)(5660300001)(229853002)(7736002)(77096006)(305945005)(6486002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0101MB1039; H:[172.19.254.107]; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
Received-SPF: None (protection.outlook.com: arbor.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 23:NQVdoRANruXfk34s/ycZnOSDRy/pl6DoDitJLYEHp9yHoNL/5cfn5Ih9GHx91DQw9PymOyzThmcDH1DG5LW2quteb2P1a5/bxQnFboHzTw/OG0yzDPJ/jEVHJkj7lERRYRp+TZuj/JDK7RnHOEhgidYu7hcl59rBLHT5QLDRl8cFYIafZrKH34YjBj/+YqGfTCrd/xIQ8iht3cm6LKuzEis12jZxMamXB7OmhkComNINv9jS72XI3IGabrvuEO7Mxfq3V6t/hSpK4Zej5ZVmSRT9pUimNLMwvXFTDcbL5O8fQC10gnNrU7HcdIAei1o1fXIgmdkvvjpHCY2rAWhv4Xq3DsHPvrm/16vh+k5lOrLUeEeEoTqQk2SY9sUfJ0gcWdZCSL0Wrjvme9w2VRbKzKOiov49XCHHODz0bmQHl6ANnKsZZ0auCnvKJD3w94I4kDA119zMa42lwE5uR8OWlGUUE/lFKN/Zr4UyOy31ngAz0hdXu26QR7RLqN4xBL4d3uARMCP/ZQlOubD/DgxFVjL9GljWMgaP39fTY1idinAqwN2OYV0ZC9Giwo70ougr1y1O6bTWIrzynVl85bT8nUImprvmc+2T7iesfCUzycemR+f3jTtJ9DxHKHkc47wDGxznVKy2u068AD78q8sOGFQ5r6c7AllxTTfOrOmcOs+kr8S8DztDLGuigOR1H5SaBUDDg93ElLrEG1ghyWwXly0VK9KrAvi4MRNEc1WidT7iThNT/LJT+pgv4vXyj2JR0V6cL7OAeY72H/YxZfEBgubc7r/CC8SVDc8HGE985W4GrHbCKAB3w+Q3STq3BaoGLux7n/E9Nv+ljW3sCQpnkyH01Xvt4Ua1JUibazsdrt4f2ROEgxfgvjIR9DmBl9LA2+1sTxxB9lVJVABoPsY0FPvkfRF4y4WwJuEzwV9Og9POpRGTr692mb5GiYMwLD4wr57I6uMdQEcXlWSE41U8SkH1kJ3/7gubR8dvcz8jHCnVvZbKi5YFVTXksoLVcCAtmLi/sU1/6XHNro+2aB22Jn+mhfrbhOxNxllxt2IkbtfdlwcSBxVg+gqv95y+PewtyHCQpz+8FN9Mj4GAIVkfav1XH7O4+4slwk53ZMs53H3LP/QrpvopJWaHL8Vam5JppQ9IQ060EgGrhTYBirbPmvVhKWw8L+WCOmpt+G/1GpTDzPHHXOEtV4C5JjK3RraP1wttC2T1pngsZgOEzrYE0bfZXY6vqWYUNitKGpbe215dMW+LOnNZ++6uvXWz95svsEH8oVu+f1ThQEJru20QOhSvK+4XEpOdqPu2kv5DjXs3FvqK79zgLuR2xdVj6wKwAwzvEfR+kvjSTeV8Ztp83Q==
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB1039; 6:fdp2itaT3cIVgutiqWLN93WV5BJuZjsxONB5a/cdcxfxJRLDjEEZP78FgkKZgcxnGZ7Mi45Xh+koUItielJBcVmdssRefzBSOhDRx2Nce1+neXCUZe5zzuRgV5xW2D/ykP6FA9eL48exdhw1XhdIug2yXZvPwJY41t6ty2bGvSpHkc3CyRvltmnrM6WySQUd0zQUoaEuj2pZh3eEOmhsxxHagJ80YQk6FXl5U5+IYJ/9fiBqyUnTsKM5r6VmNnCWQRzzyxY6cKiG1ez9UySqueswbOI/eiEh3nkf/gVMlo6WYeaF2+jB/bnPASxsCAmdLEakZL7OMvMF+LpNKSt5gA==; 5:sxnEmu+DEs7cWPbE6O7z33VbqwOM3L9rRV+ts1ukN/DA9C1MfTBjnRUz4y+8WvV0868lccQ2a5CY5Fo8SmO9TRM9UZWesSF52KzfLQVbJ85HqqLLNUGp5vYL0SD0zJogqQitYF5MM93yZnQRuzdHNw==; 24:j7vofQvGrOQYwkhYWpKYgHWWLQQX57U1hktkRISw9unPZke/tduk2oNeAsc3rUWMKK4pMbr/DW5C5lN1wB2JX85RzrtZ0UinZlc3GKrq1mk=; 7:SoeW2LYHSRGRHBWUDa34vE+wbAGF7cCxVORn+OAUIZeuSee/WWiJr2eoPrc5OVLjDvkMaFFRKbO9x2Q1by496UzQogqCyCp9zt9K3SfhcgICQ0Cj433VO5LGVEuFSL+yiHg+LM5sptWOZTKKVG3SVSR8QEfG6jeT8azGbnLFo59AABOJIKL47oWTL25fJke7OQyyfbaw4d5MK9aS0xTgk6P1OheHWDXgw0JNnfasCYo=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: arbor.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 03 Aug 2017 08:04:49.8762 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB1039
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/m6rdFdlUxRiese9igZ__NSqL1Gs>
Subject: Re: [Dots] Signal / Data / Alias / Filter Implementation
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Aug 2017 08:04:54 -0000

On 3 Aug 2017, at 14:56, Jon Shallow wrote:

> I am of the firm opinion that destination-ip is REQUIRED

The intent of DOTS is NOT to re-create flowspec.

It's to signal the need for DDoS mitigation.

'Taking out someone else's IP' is not a concern of DOTS itself; this has 
to do with the provisioning of the DOTS clients, servers, and associated 
detection/classification/traceback/mitigation systems.

Getting into layer-4 traffic descriptors, including things like 
non-initial fragments, is re-creating flowspec and IPFIX.  We don't 
intend to do that.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>