Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt

Tony Przygienda <tonysietf@gmail.com> Mon, 20 July 2015 16:20 UTC

Return-Path: <tonysietf@gmail.com>
X-Original-To: isis-wg@ietfa.amsl.com
Delivered-To: isis-wg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCFA01A8A66 for <isis-wg@ietfa.amsl.com>; Mon, 20 Jul 2015 09:20:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J6C04dlF5Mqn for <isis-wg@ietfa.amsl.com>; Mon, 20 Jul 2015 09:20:53 -0700 (PDT)
Received: from mail-ie0-x230.google.com (mail-ie0-x230.google.com [IPv6:2607:f8b0:4001:c03::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7315E1A8899 for <isis-wg@ietf.org>; Mon, 20 Jul 2015 09:20:53 -0700 (PDT)
Received: by iebmu5 with SMTP id mu5so121075354ieb.1 for <isis-wg@ietf.org>; Mon, 20 Jul 2015 09:20:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=ZVqotns9Gc5/a63P56d9j1wdQroHNQ1OPxqSFgRF8Bg=; b=j1IJqVvTgb6L4SFyEg51x4sXIhRIPaWf0Y/UYZEEo4JMXi8lFlIfmkk9POUZuivYtW M/SJ1iB99hDhElFpRDBHxAAUP5ly+7Y4rWy7xpho1JrElwMI1Fw9mJ2ZpS42SMoR7PwN 6MtIt4rrDMWreP0ibRyJJ4lSj6zYMMz4rtoZV9H9OmqpVK14SENKaMImXnbkVJtMP+N1 0iWWKLhCBOUKcNUIvsXVF9w6ornZ8jAt+xzRaBSkwD1Vy6XDHkapugKUiyiSAQstXFnS r/XA1O1RwTR+I2gYdqGfJuRuUK/pznC4DUR6wrjzvaOkVl4KSpt/HSl5zFIetIpoYXM8 09xw==
MIME-Version: 1.0
X-Received: by 10.107.129.215 with SMTP id l84mr21079026ioi.78.1437409252918; Mon, 20 Jul 2015 09:20:52 -0700 (PDT)
Received: by 10.107.52.79 with HTTP; Mon, 20 Jul 2015 09:20:52 -0700 (PDT)
In-Reply-To: <F3ADE4747C9E124B89F0ED2180CC814F5949BA31@xmb-aln-x02.cisco.com>
References: <770_1436211470_559AD90E_770_16843_1_36185c15-983d-4b98-8b77-109c5a808142@OPEXCLILMA2.corporate.adroot.infra.ftgroup> <30835_1437404233_55AD0C49_30835_3864_1_53C29892C857584299CBF5D05346208A0F5F8FCD@OPEXCLILM21.corporate.adroot.infra.ftgroup> <F3ADE4747C9E124B89F0ED2180CC814F5949BA31@xmb-aln-x02.cisco.com>
Date: Mon, 20 Jul 2015 09:20:52 -0700
Message-ID: <CA+wi2hP8k_qt+WH3B+x7GBgh7Hvc9UTDoEmDM85FjpFrBtoqWw@mail.gmail.com>
From: Tony Przygienda <tonysietf@gmail.com>
To: "Les Ginsberg (ginsberg)" <ginsberg@cisco.com>
Content-Type: multipart/alternative; boundary="001a113ec6aceacce8051b50eb16"
Archived-At: <http://mailarchive.ietf.org/arch/msg/isis-wg/J06kYxlRFAdT8nBHOwoRgPOF5oo>
Cc: "bruno.decraene@orange.com" <bruno.decraene@orange.com>, "isis-wg@ietf.org list" <isis-wg@ietf.org>
Subject: Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt
X-BeenThere: isis-wg@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF IS-IS working group <isis-wg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/isis-wg/>
List-Post: <mailto:isis-wg@ietf.org>
List-Help: <mailto:isis-wg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Jul 2015 16:20:58 -0000

Unfortunately yes.

Albeit small, this is a completely open attack vector that can melt a big
network down just nicely.

One can only appeal otherwise to 'security by obscurity' claiming that an
adjacency is necessary first and those are keyed.   However, nothing
prevents an attacker from replaying the flooding it snoops masquerading as
any of the peers while squishing the lifetimes. Or a freakish corruption
may cause the effect (this however would have been noticed long ago IMO
[just like purging on corrupt LSPs was] so I doubt that's a valid argument
within realm of likely occurrences).

So, I would say this problem is in fact a valid problem worth tackling
albeit few people in the world have it ;-) However, those people run some
stuff I wouldn't like to see going down since I cherish a working Internet
;-)

--- tony

On Mon, Jul 20, 2015 at 9:03 AM, Les Ginsberg (ginsberg) <ginsberg@cisco.com
> wrote:

> To add to what Bruno has said:
>
> In https://tools.ietf.org/id/draft-ietf-karp-isis-analysis-07.txt Section
> 2.3.2 there is the following paragraph:
>
> A rogue system having access to the common key used to protect
>        the LSP, can send an LSP, setting the Remaining Lifetime field to
>        zero, and flooding it thereby initiating a purge.  Subsequently,
>        this also can cause the sequence number of all the LSPs to
>        increase quickly to max out the sequence number space, which can
>        cause an IS to shut down for MaxAge + ZeroAgeLifetime period to
>        allow the old LSPs to age out in other ISes of the same flooding
>        domain.
>
> But this is NOT the issue discussed in Bruno's draft. In particular the
> problem Bruno discusses does not require the attacker to have the key and
> the attacker does NOT set RemainingLifetime to 0- it sets it to a small
> non-zero value.
>
> These distinctions are important because in Bruno's scenario it is not
> necessary for the attacker to have the authentication key - yet they can
> still cause LSPs to be purged prematurely.
>
>     Les
>
> > -----Original Message-----
> > From: Isis-wg [mailto:isis-wg-bounces@ietf.org] On Behalf Of
> > bruno.decraene@orange.com
> > Sent: Monday, July 20, 2015 7:57 AM
> > To: isis-wg@ietf.org list
> > Subject: Re: [Isis-wg]
> draft-decraene-isis-lsp-lifetime-problem-statement-
> > 00.txt
> >
> > Follow up on a comment expressed during the presentation:
> >  draft-ietf-karp-isis-analysis do _not_  talk about this problem
> statement.
> >
> > > -----Original Message-----
> > > From: Isis-wg [mailto:isis-wg-bounces@ietf.org] On Behalf Of
> > > bruno.decraene@orange.com
> > > Sent: Monday, July 06, 2015 9:38 PM
> > > To: isis-wg@ietf.org list
> > > Cc: SCHMITZ Christof IMT/OLN
> > > Subject: [Isis-wg]
> > > draft-decraene-isis-lsp-lifetime-problem-statement-00.txt
> > >
> > > Hi all,
> > >
> > > Please find below a draft describing the problem statement with
> > > regards to the possible corruption of the LSP lifetime.
> > > https://tools.ietf.org/html/draft-decraene-isis-lsp-lifetime-problem-
> > > statement-00
> > >
> > > Comments welcomed.
> > >
> > > Thanks,
> > > Regards,
> > > Bruno, Christof
> > >
> > > -----Original Message-----
> > > From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> > > Sent: Monday, July 06, 2015 9:29 PM
> > >
> > >
> > >
> > > A new version of I-D,
> > > draft-decraene-isis-lsp-lifetime-problem-statement-
> > > 00.txt
> > > has been successfully submitted by Bruno Decraene and posted to the
> > > IETF repository.
> > >
> > > Name:               draft-decraene-isis-lsp-lifetime-problem-statement
> > > Revision:   00
> > > Title:              IS-IS LSP lifetime corruption - Problem Statement
> > > Document date:      2015-07-06
> > > Group:              Individual Submission
> > > Pages:              6
> > > URL:
> https://www.ietf.org/internet-drafts/draft-decraene-isis-lsp-
> > > lifetime-problem-statement-00.txt
> > > Status:
> https://datatracker.ietf.org/doc/draft-decraene-isis-lsp-
> > > lifetime-problem-statement/
> > > Htmlized:
> https://tools.ietf.org/html/draft-decraene-isis-lsp-lifetime-
> > > problem-statement-00
> > >
> > >
> > > Abstract:
> > >    The IS-IS protocol exchanges Link State Packet (LSP) to exchange
> > >    routing information.  The lifetime of this LSP is located in the LSP
> > >    header and is neither protected from corruption by the Fletcher
> > >    checksum nor by cryptographic authentication.  So the LSP lifetime
> > >    may be altered, either accidentally or maliciously any time.
> > >
> > >    The lifetime field of the LSP is an important field for the correct
> > >    operation of IS-IS.  Corruption of this LSP lifetime may cause
> > >    flooding storm with severe impact in the network.
> > >
> > >    This draft documents the problem statement and calls for a solution.
> > >
> > >
> > >
> > >
> > >
> > __________________________________________________________
> > ____
> > >
> > __________________________________________________________
> > _
> > >
> > > Ce message et ses pieces jointes peuvent contenir des informations
> > > confidentielles ou privilegiees et ne doivent donc pas etre diffuses,
> > > exploites ou copies sans autorisation. Si vous avez recu ce message
> > > par erreur, veuillez le signaler a l'expediteur et le detruire ainsi
> > > que les pieces jointes. Les messages electroniques etant susceptibles
> > > d'alteration, Orange decline toute responsabilite si ce message a ete
> > > altere, deforme ou falsifie. Merci.
> > >
> > > This message and its attachments may contain confidential or
> > > privileged information that may be protected by law; they should not
> > > be distributed, used or copied without authorisation.
> > > If you have received this email in error, please notify the sender and
> > > delete this message and its attachments.
> > > As emails may be altered, Orange is not liable for messages that have
> > > been modified, changed or falsified.
> > > Thank you.
> > >
> > > _______________________________________________
> > > Isis-wg mailing list
> > > Isis-wg@ietf.org
> > > https://www.ietf.org/mailman/listinfo/isis-wg
> >
> > __________________________________________________________
> > __________________________________________________________
> > _____
> >
> > Ce message et ses pieces jointes peuvent contenir des informations
> > confidentielles ou privilegiees et ne doivent donc pas etre diffuses,
> exploites
> > ou copies sans autorisation. Si vous avez recu ce message par erreur,
> veuillez
> > le signaler a l'expediteur et le detruire ainsi que les pieces jointes.
> Les
> > messages electroniques etant susceptibles d'alteration, Orange decline
> toute
> > responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
> >
> > This message and its attachments may contain confidential or privileged
> > information that may be protected by law; they should not be distributed,
> > used or copied without authorisation.
> > If you have received this email in error, please notify the sender and
> delete
> > this message and its attachments.
> > As emails may be altered, Orange is not liable for messages that have
> been
> > modified, changed or falsified.
> > Thank you.
> >
> > _______________________________________________
> > Isis-wg mailing list
> > Isis-wg@ietf.org
> > https://www.ietf.org/mailman/listinfo/isis-wg
>
> _______________________________________________
> Isis-wg mailing list
> Isis-wg@ietf.org
> https://www.ietf.org/mailman/listinfo/isis-wg
>