Re: [Dots] TR: New Version Notification for draft-reddy-dots-telemetry-04.txt

<mohamed.boucadair@orange.com> Wed, 13 November 2019 09:40 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 324871201AA; Wed, 13 Nov 2019 01:40:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HPqGJS2g_meo; Wed, 13 Nov 2019 01:40:11 -0800 (PST)
Received: from relais-inet.orange.com (relais-inet.orange.com [80.12.66.40]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0966D12018D; Wed, 13 Nov 2019 01:40:11 -0800 (PST)
Received: from opfedar04.francetelecom.fr (unknown [xx.xx.xx.6]) by opfedar26.francetelecom.fr (ESMTP service) with ESMTP id 47CfjP236pzFpx2; Wed, 13 Nov 2019 10:40:09 +0100 (CET)
Received: from Exchangemail-eme6.itn.ftgroup (unknown [xx.xx.13.95]) by opfedar04.francetelecom.fr (ESMTP service) with ESMTP id 47CfjP0Q1gz1xpN; Wed, 13 Nov 2019 10:40:09 +0100 (CET)
Received: from OPEXCAUBMA2.corporate.adroot.infra.ftgroup ([fe80::e878:bd0:c89e:5b42]) by OPEXCAUBM24.corporate.adroot.infra.ftgroup ([::1]) with mapi id 14.03.0468.000; Wed, 13 Nov 2019 10:40:08 +0100
From: mohamed.boucadair@orange.com
To: H Y <yuuhei.hayashi@gmail.com>, "draft-reddy-dots-telemetry@ietf.org" <draft-reddy-dots-telemetry@ietf.org>
CC: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] TR: New Version Notification for draft-reddy-dots-telemetry-04.txt
Thread-Index: AQHVhZcTqLIZd9IRTUy9z3OirX19/adgIwpAgCjHvwCAABRS8A==
Date: Wed, 13 Nov 2019 09:40:08 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B9330313CD681@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
References: <157139119677.3853.16590465405127507911.idtracker@ietfa.amsl.com> <787AE7BB302AE849A7480A190F8B9330313410DA@OPEXCAUBMA2.corporate.adroot.infra.ftgroup> <CAA8pjUM2gRESrirgTux=RzDN8nWn89C+ptd1gDZnDZahoh7Q8A@mail.gmail.com>
In-Reply-To: <CAA8pjUM2gRESrirgTux=RzDN8nWn89C+ptd1gDZnDZahoh7Q8A@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.114.13.245]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/pW14mIjAP-GFx1v8YPf6Wn91tsQ>
Subject: Re: [Dots] TR: New Version Notification for draft-reddy-dots-telemetry-04.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2019 09:40:13 -0000

Hi Yuhei, 

A victim (target) can be identified by one or + target-prefixes. 

The YANG module allows to return many pre-mitigations; each with a target clause:

             +--rw pre-mitigation* [telemetry-id]
                +--rw telemetry-id                     uint32
                +--rw target
                ...
                +--ro attack-detail
                   ...
                   | 
                   +--ro top-talker

A server can aggregate top-talkers for all targets of a domain, or when justified, send specific information (including top-talkers) per individual targets.

Cheers,
Med

> -----Message d'origine-----
> De : H Y [mailto:yuuhei.hayashi@gmail.com]
> Envoyé : mercredi 13 novembre 2019 10:19
> À : draft-reddy-dots-telemetry@ietf.org
> Cc : dots@ietf.org
> Objet : Re: [Dots] TR: New Version Notification for draft-reddy-dots-
> telemetry-04.txt
> 
> Hi draft authors,
> 
> Thank you for updating the draft. I have a question about YANG module
> of current DOTS telemetry, especially about top-talker.
> 
> I think that top-talker has several meaning in general. Which
> top-talker can the YANG module explain?
>  1) Top-talker of victims.
>  2) Top-talker of each victim.
> # IMO, current YANG module can explain 1) , but can not 2) when
> target-prefix* has several elements.
> 
> I attached a slide about the question. I'm glad if you answer the question.
> 
> Thanks,
> Yuhei
> 
> 2019年10月18日(金) 18:38 <mohamed.boucadair@orange.com>:
> >
> > Hi all,
> >
> > Although we are waiting for a call for adoption for this draft, we made
> some changes which you can track with the diff provided below.
> >
> > Cheers,
> > Med
> >
> > > -----Message d'origine-----
> > > De : internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> > > Envoyé : vendredi 18 octobre 2019 11:33
> > > À : chenmeiling; BOUCADAIR Mohamed TGI/OLN; Meiling Chen; Tirumaleswar
> > > Reddy; Ehud Doron; Reddy K
> > > Objet : New Version Notification for draft-reddy-dots-telemetry-04.txt
> > >
> > >
> > > A new version of I-D, draft-reddy-dots-telemetry-04.txt
> > > has been successfully submitted by Mohamed Boucadair and posted to the
> > > IETF repository.
> > >
> > > Name:         draft-reddy-dots-telemetry
> > > Revision:     04
> > > Title:                Distributed Denial-of-Service Open Threat
> Signaling (DOTS)
> > > Telemetry
> > > Document date:        2019-10-18
> > > Group:                Individual Submission
> > > Pages:                41
> > > URL:            https://www.ietf.org/internet-drafts/draft-reddy-dots-
> > > telemetry-04.txt
> > > Status:         https://datatracker.ietf.org/doc/draft-reddy-dots-
> > > telemetry/
> > > Htmlized:       https://tools.ietf.org/html/draft-reddy-dots-telemetry-
> 04
> > > Htmlized:       https://datatracker.ietf.org/doc/html/draft-reddy-dots-
> > > telemetry
> > > Diff:           https://www.ietf.org/rfcdiff?url2=draft-reddy-dots-
> > > telemetry-04
> > >
> > > Abstract:
> > >    This document aims to enrich DOTS signal channel protocol with
> > >    various telemetry attributes allowing optimal DDoS attack mitigation