Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt

Uma Chunduri <uma.chunduri@ericsson.com> Mon, 20 July 2015 16:30 UTC

Return-Path: <uma.chunduri@ericsson.com>
X-Original-To: isis-wg@ietfa.amsl.com
Delivered-To: isis-wg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 848C31ACD72 for <isis-wg@ietfa.amsl.com>; Mon, 20 Jul 2015 09:30:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZUS5cJWh84Hr for <isis-wg@ietfa.amsl.com>; Mon, 20 Jul 2015 09:29:59 -0700 (PDT)
Received: from usevmg21.ericsson.net (usevmg21.ericsson.net [198.24.6.65]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B55ED1ACD70 for <isis-wg@ietf.org>; Mon, 20 Jul 2015 09:29:58 -0700 (PDT)
X-AuditID: c6180641-f794d6d000001dfb-35-55acba1200d0
Received: from EUSAAHC006.ericsson.se (Unknown_Domain [147.117.188.90]) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id C1.F7.07675.21ABCA55; Mon, 20 Jul 2015 11:06:27 +0200 (CEST)
Received: from EUSAAMB105.ericsson.se ([147.117.188.122]) by EUSAAHC006.ericsson.se ([147.117.188.90]) with mapi id 14.03.0210.002; Mon, 20 Jul 2015 12:29:56 -0400
From: Uma Chunduri <uma.chunduri@ericsson.com>
To: Tony Przygienda <tonysietf@gmail.com>, "Les Ginsberg (ginsberg)" <ginsberg@cisco.com>
Thread-Topic: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt
Thread-Index: AdC4Ipx32lu/9PxwSImAiodC6BhewAK2E9egAAKIimAACSE9AAAIJheA
Date: Mon, 20 Jul 2015 16:29:56 +0000
Message-ID: <1B502206DFA0C544B7A60469152008635129C22F@eusaamb105.ericsson.se>
References: <770_1436211470_559AD90E_770_16843_1_36185c15-983d-4b98-8b77-109c5a808142@OPEXCLILMA2.corporate.adroot.infra.ftgroup> <30835_1437404233_55AD0C49_30835_3864_1_53C29892C857584299CBF5D05346208A0F5F8FCD@OPEXCLILM21.corporate.adroot.infra.ftgroup> <F3ADE4747C9E124B89F0ED2180CC814F5949BA31@xmb-aln-x02.cisco.com> <CA+wi2hP8k_qt+WH3B+x7GBgh7Hvc9UTDoEmDM85FjpFrBtoqWw@mail.gmail.com>
In-Reply-To: <CA+wi2hP8k_qt+WH3B+x7GBgh7Hvc9UTDoEmDM85FjpFrBtoqWw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [147.117.188.10]
Content-Type: multipart/alternative; boundary="_000_1B502206DFA0C544B7A60469152008635129C22Feusaamb105erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFuplkeLIzCtJLcpLzFFi42KZXLonSld415pQg5NLmC1+7JjDbLHhz0Z2 i6OH3rNa7H6wkcWBxWPK742sHjtn3WX3WLLkJ5NHy7OTbAEsUVw2Kak5mWWpRfp2CVwZ665c Yi74M5Gp4tHBFSwNjE+6mLoYOTkkBEwkdvZfY4GwxSQu3FvPBmILCRxllOieJNTFyAVkL2eU ePuzF6yBTUBP4uPUn+wgtohAtMTrV+9ZQWxmgUyJP71PGLsYOTiEBYIk1i4uhygJlni3fQEj hO0m8XvHGWYQm0VAVWLepTVgI3kFfCW2f9vHBLGri1ni2dsXYA2cAoESD3dMAWtgBDru+ymI BmYBcYlbT+ZDPSAgsWTPeWYIW1Ti5eN/rBC2ksSkpeegbsuXeDzjINQyQYmTM5+wTGAUnYVk 1CwkZbOQlM0CeodZQFNi/S59iBJFiSndD9khbA2J1jlz2ZHFFzCyr2LkKC1OLctNNzLcxAiM v2MSbI47GBd8sjzEKMDBqMTDm7B2dagQa2JZcWXuIUZpDhYlcV5pv7xQIYH0xJLU7NTUgtSi +KLSnNTiQ4xMHJxSDYy6kQzVjybYcvz94nywtrX45NOwGhGOtn3GrVuWnf7petdI598c8dOs R9z11gonPLf6L/Rrn+/0WmcFzirnqlu8s68d6Lv9vmcdT90G7kr/y2lPp7gv4jlo9/mPxR8p 13R/8TUvhI7//LGcM6PS99eXX79v+rRkqGh0bT/5ldU0T/7jzxmeQtOVWIozEg21mIuKEwE0 FkproAIAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/isis-wg/pROJ2DSUdhtuYTiVqy-DDZveJKs>
Cc: "bruno.decraene@orange.com" <bruno.decraene@orange.com>, "isis-wg@ietf.org list" <isis-wg@ietf.org>
Subject: Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt
X-BeenThere: isis-wg@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF IS-IS working group <isis-wg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/isis-wg/>
List-Post: <mailto:isis-wg@ietf.org>
List-Help: <mailto:isis-wg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Jul 2015 16:30:05 -0000

Agree -

1.       It’s different than what’s discussed in the KARP draft

2.       It’s good to solve this issue in a backward compatible way, which can eventually rolled out in all nodes of the network.

--
Uma C.

From: Isis-wg [mailto:isis-wg-bounces@ietf.org] On Behalf Of Tony Przygienda
Sent: Monday, July 20, 2015 9:21 AM
To: Les Ginsberg (ginsberg)
Cc: bruno.decraene@orange.com; isis-wg@ietf.org list
Subject: Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-00.txt

Unfortunately yes.

Albeit small, this is a completely open attack vector that can melt a big network down just nicely.

One can only appeal otherwise to 'security by obscurity' claiming that an adjacency is necessary first and those are keyed.   However, nothing prevents an attacker from replaying the flooding it snoops masquerading as any of the peers while squishing the lifetimes. Or a freakish corruption may cause the effect (this however would have been noticed long ago IMO [just like purging on corrupt LSPs was] so I doubt that's a valid argument within realm of likely occurrences).

So, I would say this problem is in fact a valid problem worth tackling albeit few people in the world have it ;-) However, those people run some stuff I wouldn't like to see going down since I cherish a working Internet ;-)

--- tony

On Mon, Jul 20, 2015 at 9:03 AM, Les Ginsberg (ginsberg) <ginsberg@cisco.com<mailto:ginsberg@cisco.com>> wrote:
To add to what Bruno has said:

In https://tools.ietf.org/id/draft-ietf-karp-isis-analysis-07.txt Section 2.3.2 there is the following paragraph:

A rogue system having access to the common key used to protect
       the LSP, can send an LSP, setting the Remaining Lifetime field to
       zero, and flooding it thereby initiating a purge.  Subsequently,
       this also can cause the sequence number of all the LSPs to
       increase quickly to max out the sequence number space, which can
       cause an IS to shut down for MaxAge + ZeroAgeLifetime period to
       allow the old LSPs to age out in other ISes of the same flooding
       domain.

But this is NOT the issue discussed in Bruno's draft. In particular the problem Bruno discusses does not require the attacker to have the key and the attacker does NOT set RemainingLifetime to 0- it sets it to a small non-zero value.

These distinctions are important because in Bruno's scenario it is not necessary for the attacker to have the authentication key - yet they can still cause LSPs to be purged prematurely.

    Les

> -----Original Message-----
> From: Isis-wg [mailto:isis-wg-bounces@ietf.org<mailto:isis-wg-bounces@ietf.org>] On Behalf Of
> bruno.decraene@orange.com<mailto:bruno.decraene@orange.com>
> Sent: Monday, July 20, 2015 7:57 AM
> To: isis-wg@ietf.org<mailto:isis-wg@ietf.org> list
> Subject: Re: [Isis-wg] draft-decraene-isis-lsp-lifetime-problem-statement-
> 00.txt
>
> Follow up on a comment expressed during the presentation:
>  draft-ietf-karp-isis-analysis do _not_  talk about this problem statement.
>
> > -----Original Message-----
> > From: Isis-wg [mailto:isis-wg-bounces@ietf.org<mailto:isis-wg-bounces@ietf.org>] On Behalf Of
> > bruno.decraene@orange.com<mailto:bruno.decraene@orange.com>
> > Sent: Monday, July 06, 2015 9:38 PM
> > To: isis-wg@ietf.org<mailto:isis-wg@ietf.org> list
> > Cc: SCHMITZ Christof IMT/OLN
> > Subject: [Isis-wg]
> > draft-decraene-isis-lsp-lifetime-problem-statement-00.txt
> >
> > Hi all,
> >
> > Please find below a draft describing the problem statement with
> > regards to the possible corruption of the LSP lifetime.
> > https://tools.ietf.org/html/draft-decraene-isis-lsp-lifetime-problem-
> > statement-00
> >
> > Comments welcomed.
> >
> > Thanks,
> > Regards,
> > Bruno, Christof
> >
> > -----Original Message-----
> > From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> [mailto:internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>]
> > Sent: Monday, July 06, 2015 9:29 PM
> >
> >
> >
> > A new version of I-D,
> > draft-decraene-isis-lsp-lifetime-problem-statement-
> > 00.txt
> > has been successfully submitted by Bruno Decraene and posted to the
> > IETF repository.
> >
> > Name:               draft-decraene-isis-lsp-lifetime-problem-statement
> > Revision:   00
> > Title:              IS-IS LSP lifetime corruption - Problem Statement
> > Document date:      2015-07-06
> > Group:              Individual Submission
> > Pages:              6
> > URL:            https://www.ietf.org/internet-drafts/draft-decraene-isis-lsp-
> > lifetime-problem-statement-00.txt
> > Status:         https://datatracker.ietf.org/doc/draft-decraene-isis-lsp-
> > lifetime-problem-statement/
> > Htmlized:       https://tools.ietf.org/html/draft-decraene-isis-lsp-lifetime-
> > problem-statement-00
> >
> >
> > Abstract:
> >    The IS-IS protocol exchanges Link State Packet (LSP) to exchange
> >    routing information.  The lifetime of this LSP is located in the LSP
> >    header and is neither protected from corruption by the Fletcher
> >    checksum nor by cryptographic authentication.  So the LSP lifetime
> >    may be altered, either accidentally or maliciously any time.
> >
> >    The lifetime field of the LSP is an important field for the correct
> >    operation of IS-IS.  Corruption of this LSP lifetime may cause
> >    flooding storm with severe impact in the network.
> >
> >    This draft documents the problem statement and calls for a solution.
> >
> >
> >
> >
> >
> __________________________________________________________
> ____
> >
> __________________________________________________________
> _
> >
> > Ce message et ses pieces jointes peuvent contenir des informations
> > confidentielles ou privilegiees et ne doivent donc pas etre diffuses,
> > exploites ou copies sans autorisation. Si vous avez recu ce message
> > par erreur, veuillez le signaler a l'expediteur et le detruire ainsi
> > que les pieces jointes. Les messages electroniques etant susceptibles
> > d'alteration, Orange decline toute responsabilite si ce message a ete
> > altere, deforme ou falsifie. Merci.
> >
> > This message and its attachments may contain confidential or
> > privileged information that may be protected by law; they should not
> > be distributed, used or copied without authorisation.
> > If you have received this email in error, please notify the sender and
> > delete this message and its attachments.
> > As emails may be altered, Orange is not liable for messages that have
> > been modified, changed or falsified.
> > Thank you.
> >
> > _______________________________________________
> > Isis-wg mailing list
> > Isis-wg@ietf.org<mailto:Isis-wg@ietf.org>
> > https://www.ietf.org/mailman/listinfo/isis-wg
>
> __________________________________________________________
> __________________________________________________________
> _____
>
> Ce message et ses pieces jointes peuvent contenir des informations
> confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites
> ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez
> le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les
> messages electroniques etant susceptibles d'alteration, Orange decline toute
> responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
>
> This message and its attachments may contain confidential or privileged
> information that may be protected by law; they should not be distributed,
> used or copied without authorisation.
> If you have received this email in error, please notify the sender and delete
> this message and its attachments.
> As emails may be altered, Orange is not liable for messages that have been
> modified, changed or falsified.
> Thank you.
>
> _______________________________________________
> Isis-wg mailing list
> Isis-wg@ietf.org<mailto:Isis-wg@ietf.org>
> https://www.ietf.org/mailman/listinfo/isis-wg

_______________________________________________
Isis-wg mailing list
Isis-wg@ietf.org<mailto:Isis-wg@ietf.org>
https://www.ietf.org/mailman/listinfo/isis-wg