Re: [I2nsf] questions about draft-kim-i2nsf-security-management-architecture-01
"Diego R. Lopez" <diego.r.lopez@telefonica.com> Sat, 22 October 2016 10:49 UTC
Return-Path: <diego.r.lopez@telefonica.com>
X-Original-To: i2nsf@ietfa.amsl.com
Delivered-To: i2nsf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 28D81129590 for <i2nsf@ietfa.amsl.com>; Sat, 22 Oct 2016 03:49:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level:
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_FILL_THIS_FORM_SHORT=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yL81TW76tbpk for <i2nsf@ietfa.amsl.com>; Sat, 22 Oct 2016 03:49:14 -0700 (PDT)
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (mail-ve1eur01on0104.outbound.protection.outlook.com [104.47.1.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D17F3129581 for <i2nsf@ietf.org>; Sat, 22 Oct 2016 03:49:13 -0700 (PDT)
Received: from AM4PR0601MB2161.eurprd06.prod.outlook.com (10.167.123.150) by AM4PR0601MB2161.eurprd06.prod.outlook.com (10.167.123.150) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.659.11; Sat, 22 Oct 2016 10:49:09 +0000
Received: from AM4PR0601MB2161.eurprd06.prod.outlook.com ([10.167.123.150]) by AM4PR0601MB2161.eurprd06.prod.outlook.com ([10.167.123.150]) with mapi id 15.01.0659.028; Sat, 22 Oct 2016 10:49:09 +0000
From: "Diego R. Lopez" <diego.r.lopez@telefonica.com>
To: "Mr. Jaehoon Paul Jeong" <jaehoon.paul@gmail.com>
Thread-Topic: [I2nsf] questions about draft-kim-i2nsf-security-management-architecture-01
Thread-Index: AQHSIBDpShm1R3QEeUiivkqhLtPzsqCyK1kAgAI4WQA=
Date: Sat, 22 Oct 2016 10:49:09 +0000
Message-ID: <E4CF99C1-EDBE-46A5-95F0-DDF6729E7961@telefonica.com>
References: <4A95BA014132FF49AE685FAB4B9F17F657F4EE78@dfweml501-mbb> <CAPK2Dezb0YMYwKwL6egygGwz8vMKC2iAxswrpgETM-YH9RowSA@mail.gmail.com> <CAPK2Dey5_NTS+oum2u0E9bTAxYRFFbKCikogKYdbk4v1nUrAxg@mail.gmail.com>
In-Reply-To: <CAPK2Dey5_NTS+oum2u0E9bTAxYRFFbKCikogKYdbk4v1nUrAxg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=diego.r.lopez@telefonica.com;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [37.158.85.85]
x-ms-office365-filtering-correlation-id: 1dacd15b-0bbd-4c24-193b-08d3fa690db5
x-microsoft-exchange-diagnostics: 1; AM4PR0601MB2161; 7:vm9Qsiprkmz4U6FPHtFD6rweIsAI6L1VsIt17TOCgH4xzZvAhyYmIOBFGNuCdYfmnZbp+JEp5vGU5phiJEQ73HP7FTJwoCob2IzPnaKEVQuAL6HvDDMro0l+kk8pEYoMHiKhZMxB7V8KrFGgALKwXdoQKM9NAQwFbU2PKUgC3lYK3tp59+s5xTxq/PZNGg0vZpfbGIFN6eDFcdnVPxM/mU5JjprxsuH82pu15/bMJm07YUzhXMgrbA0m9dyUORH0czvQMqIQ39FYTuysmo84O5bSvnA6EAT5dMsnHcDx6+8tng65LBocZGOepDgyO16f8PyxIwRzz7hOgpe/2zBvYahwwjQdmYavjxx0/FnVSgI=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:AM4PR0601MB2161;
x-microsoft-antispam-prvs: <AM4PR0601MB216166FF15742B4DD13DEC51DFD70@AM4PR0601MB2161.eurprd06.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(40392960112811)(20558992708506)(120809045254105)(192374486261705)(50582790962513);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040176)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6055026); SRVR:AM4PR0601MB2161; BCL:0; PCL:0; RULEID:; SRVR:AM4PR0601MB2161;
x-forefront-prvs: 01039C93E4
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(7916002)(377454003)(189002)(199003)(252514010)(24454002)(10400500002)(5002640100001)(19617315012)(77096005)(230783001)(15975445007)(97736004)(68736007)(6116002)(586003)(3846002)(2906002)(82746002)(102836003)(31430400001)(4326007)(110136003)(83716003)(87936001)(8936002)(86362001)(76176999)(54356999)(101416001)(3660700001)(3280700002)(50986999)(5660300001)(33656002)(2900100001)(7110500001)(189998001)(36756003)(92566002)(105586002)(66066001)(325944008)(8676002)(81156014)(122556002)(16799955002)(81166006)(7736002)(2950100002)(6916009)(7906003)(7846002)(106356001)(11100500001)(106116001)(16236675004)(15650500001)(2420400007)(19580395003)(15188155005)(19580405001)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:AM4PR0601MB2161; H:AM4PR0601MB2161.eurprd06.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: telefonica.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_E4CF99C1EDBE46A595F0DDF6729E7961telefonicacom_"
MIME-Version: 1.0
X-OriginatorOrg: telefonica.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Oct 2016 10:49:09.6473 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR0601MB2161
Archived-At: <https://mailarchive.ietf.org/arch/msg/i2nsf/gwNF0-4lAFRfUJSxf865ivmqad0>
Cc: "i2nsf@ietf.org" <i2nsf@ietf.org>, "Prof. Hyoungshick Kim" <hyoung@skku.edu>, "Pauljeong@skku.edu" <Pauljeong@skku.edu>, "skku_secu-brain_all@googlegroups.com" <skku_secu-brain_all@googlegroups.com>, Linda Dunbar <linda.dunbar@huawei.com>
Subject: Re: [I2nsf] questions about draft-kim-i2nsf-security-management-architecture-01
X-BeenThere: i2nsf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "*I2NSF: Interface to Network Security Functions mailing list*" <i2nsf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i2nsf/>
List-Post: <mailto:i2nsf@ietf.org>
List-Help: <mailto:i2nsf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 22 Oct 2016 10:49:18 -0000
Hi Paul, While I find agreeable that your draft could be merged with another one (or other ones) in order to consolidate the documents to be produced by I2NSF, I am not 100% sure it should be the framework draft. Looking at the proposals you make in your draft I see it more aligned with what the drafts dealing with the client-facing interface are considering than with the general framework. In particular, draft-kumar-i2nsf-client-facing-interface-req-01<https://datatracker.ietf.org/doc/draft-kumar-i2nsf-client-facing-interface-req/> has a section(3.3) that discusses management deployment models, and I am under the impression this architecture you propose could be seen as a refinement of those models. Be goode, On 21 Oct 2016, at 02:54 , Mr. Jaehoon Paul Jeong <jaehoon.paul@gmail.com<mailto:jaehoon.paul@gmail.com>> wrote: Hi Linda, Are you agreeing at merging our draft (draft-kim-i2nsf-security-management-architecture-02) into draft-ietf-i2nsf-framework-03? Thanks. Best Regards, Paul On Fri, Oct 7, 2016 at 5:32 AM, Mr. Jaehoon Paul Jeong <jaehoon.paul@gmail.com<mailto:jaehoon.paul@gmail.com>> wrote: Hi Linda, As a coauthor of this draft, I will answer your questions inline below. On Wed, Oct 5, 2016 at 1:34 PM, Linda Dunbar <linda.dunbar@huawei.com<mailto:linda.dunbar@huawei.com>> wrote: Hyoungshick, et al, How would you position your draft-kim-i2nsf-security-management-architecture-01 with regard to the I2NSF framework draft? I find there are a lot of duplicated content to the I2nsf framework draft. [Paul] We would like to merge our draft into the i2nsf framework draft because our draft has one depth more detailed architecture. This detailed architecture will be helpful to implement the i2nsf framework. There are some differences, such as the following: Are you trying to define how “security policy” is structured? <image002.png> [Paul] Our architecture allows an NSF to update a low-level policy and apply it to the related high-level policy via the control path of Security Controller and Policy Collector (renamed Event Collector in version 02) in Figure 1 of our version 02: https://tools.ietf.org/html/draft-kim-i2nsf-security-management-architecture-02 For example, if an NSF of firewall detects a new DoS-attack host, it reports the updated blacklist having the IP address of such a host to Application Logic in I2NSF Client via Security Controller and Event Collector. Application Logic asks Policy Updater to disseminate the updated blacklist to the security controllers under the administration of the same I2NSF Client. Will the “High Level security management” eventually lead to Client Facing Policy data models? [Paul] Yes, as explained above, the High-level security management leads to update and handle Client facing policy data models. Do you plan to define interfaces between all those components depicted in Figure 1? The interfaces between some of those components are not really in the I2NSF WG current charter, such as “Security Policy Manager” <-> “NSF Capability Manager”, or the interface between “Application Logic” <-> “Policy Updater”. [Paul] Yes, we have a plan to define such interfaces. Are those components in your current implementation? Is it like an “example of one implementation”? [Paul] Though those components are not fully implemented yet in our implementation, my team at SKKU will make implement those components in a later version. Thanks for your clarification questions. Best Regards, Paul Thanks, Linda _______________________________________________ I2nsf mailing list I2nsf@ietf.org<mailto:I2nsf@ietf.org> https://www.ietf.org/mailman/listinfo/i2nsf -- =========================== Mr. Jaehoon (Paul) Jeong, Ph.D. Assistant Professor Department of Software Sungkyunkwan University Office: +82-31-299-4957 Email: jaehoon.paul@gmail.com<mailto:jaehoon.paul@gmail.com>, pauljeong@skku.edu<mailto:pauljeong@skku.edu> Personal Homepage: http://iotlab.skku.edu/people-jaehoon-jeong.php<http://cpslab.skku.edu/people-jaehoon-jeong.php> -- =========================== Mr. Jaehoon (Paul) Jeong, Ph.D. Assistant Professor Department of Software Sungkyunkwan University Office: +82-31-299-4957 Email: jaehoon.paul@gmail.com<mailto:jaehoon.paul@gmail.com>, pauljeong@skku.edu<mailto:pauljeong@skku.edu> Personal Homepage: http://iotlab.skku.edu/people-jaehoon-jeong.php<http://cpslab.skku.edu/people-jaehoon-jeong.php> _______________________________________________ I2nsf mailing list I2nsf@ietf.org<mailto:I2nsf@ietf.org> https://www.ietf.org/mailman/listinfo/i2nsf -- "Esta vez no fallaremos, Doctor Infierno" Dr Diego R. Lopez Telefonica I+D http://people.tid.es/diego.lopez/ e-mail: diego.r.lopez@telefonica.com Tel: +34 913 129 041 Mobile: +34 682 051 091 ----------------------------------
- [I2nsf] questions about draft-kim-i2nsf-security-… Linda Dunbar
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Mr. Jaehoon Paul Jeong
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Mr. Jaehoon Paul Jeong
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Linda Dunbar
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Diego R. Lopez
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Mr. Jaehoon Paul Jeong
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Rakesh Kumar
- Re: [I2nsf] questions about draft-kim-i2nsf-secur… Mr. Jaehoon Paul Jeong