Re: 6man w.g. last call for <draft-ietf-6man-grand>

Jen Linkova <furry13@gmail.com> Thu, 23 July 2020 01:44 UTC

Return-Path: <furry13@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C24F3A0B03 for <ipv6@ietfa.amsl.com>; Wed, 22 Jul 2020 18:44:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.849
X-Spam-Level:
X-Spam-Status: No, score=-1.849 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K9nrfyDegq3X for <ipv6@ietfa.amsl.com>; Wed, 22 Jul 2020 18:44:06 -0700 (PDT)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E35133A0AFF for <ipv6@ietf.org>; Wed, 22 Jul 2020 18:44:05 -0700 (PDT)
Received: by mail-qk1-x72a.google.com with SMTP id d4so594524qkk.8 for <ipv6@ietf.org>; Wed, 22 Jul 2020 18:44:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=oo3Q8BacDiiaUDcxpWrzZB9xOnTLTd1yzufXcb6YSZE=; b=QmZc6Z/WUw2RAJzJznXUjUHmiB2xR7h5IVlK4LwA+lJeosZcBE7cf3MgHidEV6JqYx PbYofzeut9G6Ikhc9ZtYnfPtaJb/AC0h160/B+lOap7AqIeJd3L8T/N1TDYF45y96AN9 EPK1qY/Kq8VgjxJTePDkq/Os+HQMVXM5lZoIWhwNo14QYljAG2e3ix5wCLjF4blzu9K3 X7m8xwpudRMl5PacbuliO2/QSeBuy2zgyuRDjwZGJXdDZbVSrE5HcplkfT/2k1L6KfXm NslANoIW4DgpKGepB0huSKJoUTCW4Z+D8bB9RanZ2SH/3PITroMIy4BU3duesX44vLSm Hovw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=oo3Q8BacDiiaUDcxpWrzZB9xOnTLTd1yzufXcb6YSZE=; b=UVr12WpiN5xEBwauw7UgRAHQFfRIedEztsqWl5X0bIUxi5Fb4dsbGG004X8cyNBaj2 EwkVoDXJG9ko1/KrFa0NdlDP69V8Y0T0jW2ax3DjSN3PennD+PXd/TFSR9mvnrI7Ahym U6Nt8xdoMtZqRz+i7yBN8mvV7FzaHGdMV8YY6iySCoGveqJK3GDo+wChni0tKoqMQDQ1 Rx7V8FeBB+JH/tVRCkmfsC6oWSnm3ItST7ep7LlBMwF2DRYGLoJ+V8wy+8NteMCJT34v vzNZGLMPf59OIB29S2zvjIN0p/sf4eFjHr/C9r7oo5hSfZ08sSlWQ4EaA3VoT/ahDFcr oXKw==
X-Gm-Message-State: AOAM531RRT53Tzee5DyuoPK/mlOJcWzxMDRmD8qfhP3ye4LDC2K/tgKy 9ejX9xFPkwIBUZxZ/zeoEV1XgPjb/99VS31xpFM=
X-Google-Smtp-Source: ABdhPJwnDF9TGklqxwaGZV3w07JDfgR6G1Fcrpqv6WBvLaG8Rmp4/vcEFGg9H9VII9SBw8alkwhXaG0h3Wn5LbY50wI=
X-Received: by 2002:ae9:dcc6:: with SMTP id q189mr3051727qkf.332.1595468645063; Wed, 22 Jul 2020 18:44:05 -0700 (PDT)
MIME-Version: 1.0
References: <20160428004904.25189.43047.idtracker@ietfa.amsl.com> <882A1EDB-4A41-47E7-88D6-AC37D3341C6A@gmail.com> <CAO42Z2yWzcQBkDjOsaiM2Ppij0v=s1edMLyZeLbf1e89wVU3UA@mail.gmail.com> <CAFU7BAQvpHiJ9X=y72Zr5VAXs4ZGVqP1A5-snxBbrmxecPnpWA@mail.gmail.com> <CAO42Z2xLEQFbMYLUHHza3fM2O4Df=-ZC35P=ugeEbF2cs=Oiwg@mail.gmail.com> <CAFU7BATybbTPJfoLgbKGW8_U2HRSze2yBRx+Y8BS5N12SK1BTA@mail.gmail.com> <CAO42Z2zfgdDJn3dv6OHqpKySsW_2rvkV-W15BM-UsVq51nQMMQ@mail.gmail.com> <CAFU7BAQq3b8Og-MC_bFOMAZpL2N67so1gy=APS+6VLS0-u+JyA@mail.gmail.com>
In-Reply-To: <CAFU7BAQq3b8Og-MC_bFOMAZpL2N67so1gy=APS+6VLS0-u+JyA@mail.gmail.com>
From: Jen Linkova <furry13@gmail.com>
Date: Thu, 23 Jul 2020 11:43:53 +1000
Message-ID: <CAFU7BAQXYmig703yKsDLK-pb7KEd-PuiFQspWbhaZv-kzusAkw@mail.gmail.com>
Subject: Re: 6man w.g. last call for <draft-ietf-6man-grand>
To: Mark Smith <markzzzsmith@gmail.com>
Cc: Bob Hinden <bob.hinden@gmail.com>, Jen Linkova <furry@google.com>, IPv6 List <ipv6@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/Sf4csiiyvxlaM0u_vjWk2hgf-lc>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jul 2020 01:44:07 -0000

On Thu, Jul 23, 2020 at 11:15 AM Jen Linkova <furry13@gmail.com> wrote:
> > - helping mitigate ND cache exhaustion DoS attack by preloading the
> > cache with addresses
>
> I'm not sure I fully understand how it would help...Could you please elaborate?
> The attack is trying to create a lot of INCOMPLETE entries by sending
> packets to non-existing addresses.
> Unless we require that routers rely on GRAND only and never even try
> to create a new entry upon receiving a packet to an address never seen
> before, the router behaviour would still be the same.

I stand corrected. Yeah, it might help as it makes it more likely that
an address which does not exist in the cache does not exist on the
network either.
So resolving such addresses could be deprioritized even more.
Funny enough the draft does say it already ;))

-- 
SY, Jen Linkova aka Furry