Re: RE : [midcom] More on new work item

Jonathan Rosenberg <jdrosen@dynamicsoft.com> Mon, 03 May 2004 13:51 UTC

Received: from optimus.ietf.org (www.iesg.org [132.151.1.19]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA29527 for <midcom-archive@odin.ietf.org>; Mon, 3 May 2004 09:51:42 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BKdhw-0006On-A6 for midcom-archive@odin.ietf.org; Mon, 03 May 2004 09:42:08 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id i43Dg8d5024597 for midcom-archive@odin.ietf.org; Mon, 3 May 2004 09:42:08 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BKd5J-0006ve-FC; Mon, 03 May 2004 09:02:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BKcwQ-0001Yi-4t for midcom@optimus.ietf.org; Mon, 03 May 2004 08:53:02 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA25867 for <midcom@ietf.org>; Mon, 3 May 2004 08:52:59 -0400 (EDT)
Received: from ietf-mx.ietf.org ([132.151.6.1] helo=ietf-mx) by ietf-mx with esmtp (Exim 4.32) id 1BKcwO-0006dw-P6 for midcom@ietf.org; Mon, 03 May 2004 08:53:00 -0400
Received: from exim by ietf-mx with spam-scanned (Exim 4.12) id 1BKcq6-0005if-00 for midcom@ietf.org; Mon, 03 May 2004 08:46:32 -0400
Received: from [63.113.44.69] (helo=mail3.dynamicsoft.com) by ietf-mx with esmtp (Exim 4.12) id 1BKckH-0004mt-00 for midcom@ietf.org; Mon, 03 May 2004 08:40:29 -0400
Received: from dynamicsoft.com ([63.113.46.116]) by mail3.dynamicsoft.com (8.12.8/8.12.1) with ESMTP id i43Cdgus023541; Mon, 3 May 2004 08:39:42 -0400 (EDT)
Message-ID: <40963D64.7060306@dynamicsoft.com>
Date: Mon, 03 May 2004 08:39:00 -0400
From: Jonathan Rosenberg <jdrosen@dynamicsoft.com>
Organization: dynamicsoft
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6) Gecko/20040113
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Joel Tran <joel.tran@USherbrooke.ca>
CC: midcom@ietf.org, 'Melinda Shore' <mshore@cisco.com>
Subject: Re: RE : [midcom] More on new work item
References: <000701c42ed4$2ec76360$b248d284@kamel>
In-Reply-To: <000701c42ed4$2ec76360$b248d284@kamel>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: quoted-printable
X-MIME-Autoconverted: from 8bit to quoted-printable by mail3.dynamicsoft.com id i43Cdgus023541
X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on ietf-mx.ietf.org
X-Spam-Status: No, hits=0.0 required=5.0 tests=AWL autolearn=no version=2.60
Content-Transfer-Encoding: quoted-printable
Sender: midcom-admin@ietf.org
Errors-To: midcom-admin@ietf.org
X-BeenThere: midcom@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/midcom>, <mailto:midcom-request@ietf.org?subject=unsubscribe>
List-Id: <midcom.ietf.org>
List-Post: <mailto:midcom@ietf.org>
List-Help: <mailto:midcom-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/midcom>, <mailto:midcom-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: quoted-printable

inline.

Joel Tran wrote:

>>-----Message d'origine-----
>>De : Jonathan Rosenberg [mailto:jdrosen@dynamicsoft.com]
>>Envoyé : 30 avril, 2004 11:42
>>À : Joel Tran
>>Cc : 'Melinda Shore'; midcom@ietf.org
>>Objet : Re: RE : [midcom] More on new work item
>>
> 
>>* if there is any other NAT intervening the user and the
>>ISP's nat (very
>>common here in the US at least, due to residential NAT devices like
>>those made by linksys), this of course won't help even if you
>>work out
>>the ACL issues
> 
> 
> Yes traversing the home NAT is a problem. Just a quick question, is there a
> solution avaible for traversing both home and ISP NAT (excluding relaying)
> when two peers are under such topology? If yes, we could probably learn form
> them how they solve the situtation.

Sure, STUN would allow this.

> 
> 
>>* assuming no other nats between the user and the ISP NAT, there is a
>>correlation that needs to be made somewhere between the
>>username/password and the IP address thats allocated to them.
>>This would
>>require some really convoluted coupling between DHCP (which
>>can tell you
>>the MAC/IP binding) and customer provisioning systems (which
>>*might* be
>>able to tell you the MAC used by a customers cable modem) and the ISP
>>firewall, to make sure that a user can only make changes for
>>their own
>>IP. This seems pretty complicated to me.
> 
> 
> I don't think we require a big correlation (User/PWD/IP) in order to provide
> a security mechanism. For example, the rules can be :
> 
>   1 - Pinholes can only be created for the source address.
>   2 - User joe can only create 10 pinholes or IP source can only create 10
> pinholes.
>   3 - ...

This rule is susceptible to source address spoofing attacks. It would 
allow me to direct traffic at a target by faking my source IP to be that 
of the target.

If you further reduce the scope of this problem by making, say, 
relatively short timeouts on the bindings that are created, and only 
allow a single port to be allocated at a time, you come to an 
interesting point - you could obtain exactly the same kind of allocation 
from a midcom-unaware NAT by sending a STUN query through it.


> 
>>* Its also not clear to me that there aren't security holes
>>in the whole
>>thing that might enable someone to learn the passwords and usernames
>>needed to control bindings for other IP addresses.
> 
> 
> I'm not an SNMPv3 expert but I think that the security mechanism
> (USM/encryption) provided by SNMPv3 is strong enough so that it will be hard
> for someone to break trough and discover the user name/password or try to
> get unrestricted access.

I was concerned more about system level security, if you try and 
correlate the username/pass with DHCP and MAC information.

-Jonathan R.

-- 
Jonathan D. Rosenberg, Ph.D.                600 Lanidex Plaza
Chief Technology Officer                    Parsippany, NJ 07054-2711
dynamicsoft
jdrosen@dynamicsoft.com                     FAX:   (973) 952-5050
http://www.jdrosen.net                      PHONE: (973) 952-5000
http://www.dynamicsoft.com

_______________________________________________
midcom mailing list
midcom@ietf.org
https://www1.ietf.org/mailman/listinfo/midcom