Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21

Kent Watsen <kwatsen@juniper.net> Fri, 23 February 2018 15:28 UTC

Return-Path: <kwatsen@juniper.net>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC1E21270A3; Fri, 23 Feb 2018 07:28:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level:
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZX1jNUJ0qEaN; Fri, 23 Feb 2018 07:28:12 -0800 (PST)
Received: from mx0b-00273201.pphosted.com (mx0a-00273201.pphosted.com [208.84.65.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8A7FB126D05; Fri, 23 Feb 2018 07:28:12 -0800 (PST)
Received: from pps.filterd (m0108157.ppops.net [127.0.0.1]) by mx0a-00273201.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w1NFP6WH026480; Fri, 23 Feb 2018 07:28:10 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=PPS1017; bh=UhdvVXSUmD+0107eQDKV0tOeNUw/SgdIVvPSZk1kFrc=; b=Rts+ZyEpIWtvrdZC6jgsNLy+lN80esoNuSomAxjvd3DktCgGJ/XLk7DnYrulivUAVOxF AQbfC/fhD/SOlmIwv5e4iW+AqhrpmuwuqbF6PF1ykdD6FKFtthAKf9iNdNgGJq/Dp6cZ /HqXZ9D06vJfXAlOZnt6iBWX8XUpr3KrdbioymvcTxJ0Mu2CS+gA4pAqBDTMqet6JKS1 8vUYZn+1p3xzAgVcAmvGC8uUwyEiKSs0yxFLvArzAWOPfUzuZSUCFVJtSft8Am+xE+FU gdql4zOf8DYO15SBcp8qVhygZfSQtUPDrZs81cZUfdQ5cmTlGdNXQZ29XLLqmkXjzUnh qg==
Received: from nam03-dm3-obe.outbound.protection.outlook.com (mail-dm3nam03lp0019.outbound.protection.outlook.com [207.46.163.19]) by mx0a-00273201.pphosted.com with ESMTP id 2gangk00fc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Fri, 23 Feb 2018 07:28:10 -0800
Received: from DM5PR05MB3484.namprd05.prod.outlook.com (10.174.240.147) by DM5PR05MB3452.namprd05.prod.outlook.com (10.174.240.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.548.6; Fri, 23 Feb 2018 15:28:08 +0000
Received: from DM5PR05MB3484.namprd05.prod.outlook.com ([fe80::507:f464:b89a:c64b]) by DM5PR05MB3484.namprd05.prod.outlook.com ([fe80::507:f464:b89a:c64b%3]) with mapi id 15.20.0548.005; Fri, 23 Feb 2018 15:28:08 +0000
From: Kent Watsen <kwatsen@juniper.net>
To: "Gary Wu (garywu)" <garywu@cisco.com>, Yaron Sheffer <yaronf.ietf@gmail.com>, "Clyde Wildes (cwildes)" <cwildes@cisco.com>
CC: "draft-ietf-netmod-syslog-model.all@ietf.org" <draft-ietf-netmod-syslog-model.all@ietf.org>, "netmod@ietf.org" <netmod@ietf.org>
Thread-Topic: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21
Thread-Index: AQHTqMUaxzdr5H1LmU6r4TNVjLpgwKOsOFkAgAAftgCAAv3XgIACeo4A
Date: Fri, 23 Feb 2018 15:28:07 +0000
Message-ID: <D0F1CC52-3D6E-44AA-87B8-2CDD5794E6A0@juniper.net>
References: <151896425742.27914.9664814474838013064@ietfa.amsl.com> <6E582464-6EDB-4D55-9E8B-BEC68929DF9A@cisco.com> <4694018c-0be5-e78c-38ed-8745da01d019@gmail.com> <F936D2F4-2D71-4B8E-B800-3E162D1B7B03@cisco.com>
In-Reply-To: <F936D2F4-2D71-4B8E-B800-3E162D1B7B03@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.20.0.170309
x-originating-ip: [66.129.241.14]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR05MB3452; 7:PUuw7Dx/T37iQmi2OfcB9+pw73kmEftuyos4iidqW8pDLFX4enMp9LNIn2/65YG7f8CnRjqrQB0d/d2EtDxO70np7sdU4ZGze+LXQy6CeUB5NlphgPT1eUrDuCXVP8eoX00MqGJhEdRb4Y+zQL7VORPEGHm//qZS/vH+8wr5iqZqgUZ20cPX5nqsMDDpHMTeQQ++fD/Fo5a+C/nmAK+5wvqrwmzTtJFSnkobeeDX95tlHN/YGlL6d67Mij0cFLQk
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 03763c01-941b-46da-35e4-08d57ad20a7b
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(4534165)(4627221)(201703031133081)(201702281549075)(48565401081)(5600026)(4604075)(3008032)(2017052603307)(7153060)(7193020); SRVR:DM5PR05MB3452;
x-ms-traffictypediagnostic: DM5PR05MB3452:
x-microsoft-antispam-prvs: <DM5PR05MB34520210294FCA05D1B72391A5CC0@DM5PR05MB3452.namprd05.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001082)(6040501)(2401047)(5005006)(8121501046)(3002001)(10201501046)(93006095)(93001095)(3231166)(944501161)(6055026)(6041288)(20161123564045)(20161123560045)(20161123562045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011); SRVR:DM5PR05MB3452; BCL:0; PCL:0; RULEID:; SRVR:DM5PR05MB3452;
x-forefront-prvs: 0592A9FDE6
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(366004)(396003)(39380400002)(39860400002)(346002)(376002)(199004)(189003)(54906003)(110136005)(6436002)(6346003)(2950100002)(7736002)(59450400001)(86362001)(305945005)(36756003)(6512007)(81166006)(53936002)(4326008)(14454004)(26005)(81156014)(33656002)(3846002)(76176011)(6506007)(93886005)(2906002)(106356001)(6486002)(478600001)(8936002)(229853002)(25786009)(5250100002)(8676002)(6116002)(102836004)(97736004)(186003)(5660300001)(99286004)(316002)(6246003)(82746002)(39060400002)(3660700001)(105586002)(83716003)(3280700002)(68736007)(66066001)(58126008)(2900100001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR05MB3452; H:DM5PR05MB3484.namprd05.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-microsoft-antispam-message-info: ECRhp5iiNn6ivzYHAsY6pmboHNgsqvtGA7DHt58Uyv1LxfAKsfx4AdiVxwMdeLDiOc96ZwLRLlcqPt2S5jF1Xovbe2PYF2E8r1dfvdRK5dPqvuHDH3Lj+zAUxPdSbWMtkjgWoGrb/P+LsVsbKjHQitvoFPb75jkhDz1inIBJLp8=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <CA8ABC1431D5D844B867B49AE3C1BEDC@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: 03763c01-941b-46da-35e4-08d57ad20a7b
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Feb 2018 15:28:07.9780 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR05MB3452
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2018-02-23_05:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1802230191
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/1gN9C0iGw-m5XmjgeRW_1_41Oxk>
Subject: Re: [netmod] Secdir last call review of draft-ietf-netmod-syslog-model-21
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Feb 2018 15:28:14 -0000


    >      Security Comments
    >      
    >      * I think almost all writable data nodes here are sensitive, because a network
    >      attacker's first move is to block any logging on the host, and many of the data
    >      nodes here can be used for this purpose.
    > 
    > [clw1] I will reword the security section to include all writeable nodes as sensitive.
    > 
    >      * Re: readable data nodes, I'm not
    >      sure which are sensitive, and the document should give an example or two rather
    >      than just say "some". Otherwise the security advice is not actionable. One
    >      example: "remote" sections leak information about other hosts in the network.
    > 
    > [clw1] This text was lifted from another model. I will review the readable nodes and update.
    > 
    >      * Write operations... can have a negative effect on network operations. - I would
    >      add "and on network security", because logs are often used to detect security
    >      breaches.
    > 
    > [clw1] I will add this phrase.
    > 

The fact that the syslog data nodes are write-sensitive can be made explicit in
the model by making the whole configuration tree nacm:default-deny-write, and
making read-sensitive subtrees nacm:default-deny-all.

Thanks,
Gary Wu


<KENT> Agreed.  Usually my modules have the NACM annotations and then, in the
Security Considerations section, I'm sure to point them out.


K.