Re: 6man w.g. last call for <draft-ietf-6man-grand>

Jen Linkova <furry13@gmail.com> Thu, 23 July 2020 01:15 UTC

Return-Path: <furry13@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 302533A0AD8 for <ipv6@ietfa.amsl.com>; Wed, 22 Jul 2020 18:15:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.849
X-Spam-Level:
X-Spam-Status: No, score=-1.849 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id poHyRnzW_04o for <ipv6@ietfa.amsl.com>; Wed, 22 Jul 2020 18:15:53 -0700 (PDT)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0FB0E3A0AD6 for <ipv6@ietf.org>; Wed, 22 Jul 2020 18:15:53 -0700 (PDT)
Received: by mail-qk1-x72a.google.com with SMTP id b14so2238205qkn.4 for <ipv6@ietf.org>; Wed, 22 Jul 2020 18:15:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=0+gQg2tiEYPEUZvLlOJfCRaehWBPuyy4W7CEWaZlhq0=; b=sku3QfkoZCzxkx1e1JIh8DNUaWId6hs4XnTuB51XNIiVRO0lEM1borp6KFS1iTXwsi k7deHvX3OUXGLji+dPJEpunIQObhD2uOFlxP8PN2xpLkEasEr3DanMH7c0wgGiYo+nHD i7LhoY4g3sxFV/SXK2YZHkTOFzo0ytE3AMnGFc/UwE7M/6euW8EZmXF7sKyiQkzS+8UN wetO7c+QR0BDPRfxRMYfjQUgf7GGWbGwF0v/Oum6mMkOH6xFqby+m0UAvfiNJ7OHfsch WrMjgUwueStAbPsWJutFni69epVsuanGj/+n5iIDjJ2YSCg8oYyklK0u0tLOtGCT2NJe yopQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=0+gQg2tiEYPEUZvLlOJfCRaehWBPuyy4W7CEWaZlhq0=; b=Xd2UK/blMcqBG1tB1x3OyZRc1lJR4b+vhxQ7wL51cnfL7ts/wbUyVBezfFMabMtj0H VxCYub/RBxVqgD6d5k4h5MEaktPscqEX1juTB90vy3h2pxxppx6qCT8ued6DXslq1LM3 MFpELKnO6Vab1qHetGDOsNPFBfpufnJIVs5sXgvM3DWHIeBDUHQmWhyrSFZE4RbVy7iQ YtQGpUKjIPPMhH1r4/7QexJwg7BpPg8MwyQ0QKP/pVD+G0Jt37v3RXGRdJ0IfCh8D0Ta 0VdMvztW64TI+u0/RiYKYGVgjOIqtkyu4U0H2PRyPqSlh7CLL8nn1Q6/P19SU0/CO0KG I4KQ==
X-Gm-Message-State: AOAM533EIaXicg1t6YpoDwk+JOrbFWdXfo4djFsaaoFTyZIJ7/h9Soa3 ilIFgYdgfilhnMQqFksT3nStf4iJI9MeO/NyLk0=
X-Google-Smtp-Source: ABdhPJx84vHByYypXyBkkGbF9qweQM9e5PxaaEsccNVQs7Hqsn0rzJXgdPSM7H1CAB8hdlsujSXqLmTuW3rQzuPlQ/8=
X-Received: by 2002:a37:6f07:: with SMTP id k7mr2719481qkc.444.1595466952105; Wed, 22 Jul 2020 18:15:52 -0700 (PDT)
MIME-Version: 1.0
References: <20160428004904.25189.43047.idtracker@ietfa.amsl.com> <882A1EDB-4A41-47E7-88D6-AC37D3341C6A@gmail.com> <CAO42Z2yWzcQBkDjOsaiM2Ppij0v=s1edMLyZeLbf1e89wVU3UA@mail.gmail.com> <CAFU7BAQvpHiJ9X=y72Zr5VAXs4ZGVqP1A5-snxBbrmxecPnpWA@mail.gmail.com> <CAO42Z2xLEQFbMYLUHHza3fM2O4Df=-ZC35P=ugeEbF2cs=Oiwg@mail.gmail.com> <CAFU7BATybbTPJfoLgbKGW8_U2HRSze2yBRx+Y8BS5N12SK1BTA@mail.gmail.com> <CAO42Z2zfgdDJn3dv6OHqpKySsW_2rvkV-W15BM-UsVq51nQMMQ@mail.gmail.com>
In-Reply-To: <CAO42Z2zfgdDJn3dv6OHqpKySsW_2rvkV-W15BM-UsVq51nQMMQ@mail.gmail.com>
From: Jen Linkova <furry13@gmail.com>
Date: Thu, 23 Jul 2020 11:15:40 +1000
Message-ID: <CAFU7BAQq3b8Og-MC_bFOMAZpL2N67so1gy=APS+6VLS0-u+JyA@mail.gmail.com>
Subject: Re: 6man w.g. last call for <draft-ietf-6man-grand>
To: Mark Smith <markzzzsmith@gmail.com>
Cc: Bob Hinden <bob.hinden@gmail.com>, Jen Linkova <furry@google.com>, IPv6 List <ipv6@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/iuDbzi1V3ipc4J99MjZohTDu0_k>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jul 2020 01:15:54 -0000

On Thu, Jul 23, 2020 at 9:01 AM Mark Smith <markzzzsmith@gmail.com> wrote:
> There are other issues that this method provides benefits to or
> solves, more than just the specific problem you're thinking about:
>
> - helping mitigate ND cache exhaustion DoS attack by preloading the
> cache with addresses

I'm not sure I fully understand how it would help...Could you please elaborate?
The attack is trying to create a lot of INCOMPLETE entries by sending
packets to non-existing addresses.
Unless we require that routers rely on GRAND only and never even try
to create a new entry upon receiving a packet to an address never seen
before, the router behaviour would still be the same.

> > The routers already have all link-local addresses of hosts on the LAN
> > in their caches.
>
> I don't understand how.

OK, I should have said 'all link-local addresses which hosts have used'.
An address which has not been used (send/receive packets) might not be
in the cache.

> Hosts aren't limited to a single link-local address on an interface,
> and could generate a new one at any time. So if a host generates a new
> LLA, it would do GRAND for it so that the routers are informed of the
> new LLA.

Well, as soon as the host starts using that LLA it would be sending ND
packets from it which would populate the cache entry anyway.
But I agree, GRAND would make it faster.

> > > I think it would be better to remove all the text around link-layer
> > > unicasting of GRAND NAs for the time being.

OK, will do in the next version.

-- 
SY, Jen Linkova aka Furry