RE: [nmrg] Re: [IRSG] review of draft-irtf-nmrg-snmp-measure-04.txt

"David B Harrington" <dbharrington@comcast.net> Mon, 19 May 2008 18:43 UTC

Received: from QMTA07.emeryville.ca.mail.comcast.net (qmta07.emeryville.ca.mail.comcast.net [76.96.30.64]) by bierator.ibr.cs.tu-bs.de (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id m4JIhe3E003951 for <nmrg@ibr.cs.tu-bs.de>; Mon, 19 May 2008 20:43:46 +0200
Received: from OMTA13.emeryville.ca.mail.comcast.net ([76.96.30.52]) by QMTA07.emeryville.ca.mail.comcast.net with comcast id TTuF1Z00117UAYkA70FV00; Mon, 19 May 2008 18:43:35 +0000
Received: from Harrington73653 ([24.128.66.199]) by OMTA13.emeryville.ca.mail.comcast.net with comcast id TWjX1Z0074HwxpC8Z00000; Mon, 19 May 2008 18:43:33 +0000
X-Authority-Analysis: v=1.0 c=1 a=zOsyX00C8WEA:10 a=1Im-IAa9KzAA:10 a=j3Z76cjpAAAA:8 a=ScMFhzVftyQFUUTUuCcA:9 a=yh1Q2r7NcGlr1b-9CGw_GpB0NqEA:4 a=FvgKqOQ44qUA:10 a=JrSEOxZJtCQA:10 a=XF7b4UCPwd8A:10
From: David B Harrington <dbharrington@comcast.net>
To: j.schoenwaelder@jacobs-university.de
References: <p06240404c456a78f0f60@[192.168.1.105]> <08cb01c8b9b2$7669edb0$0600a8c0@china.huawei.com> <20080519183102.GA28463@elstar.local>
Subject: RE: [nmrg] Re: [IRSG] review of draft-irtf-nmrg-snmp-measure-04.txt
Date: Mon, 19 May 2008 14:43:31 -0400
Message-ID: <08f401c8b9e0$3da02f20$0600a8c0@china.huawei.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 11
In-Reply-To: <20080519183102.GA28463@elstar.local>
Thread-Index: Aci53oep20LMx7XATpGWtp/3XVChrwAAa/eA
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
X-IBRFilter-SpamReport: 3.602 (***) BAYES_50, DNS_FROM_RFC_POST, RCVD_IN_SORBS_DUL
X-Scanned-By: MIMEDefang 2.51 on 134.169.34.9
Cc: 'Internet Research Steering Group' <irsg@isi.edu>, "'Karen R. Sollins'" <sollins@csail.mit.edu>, nmrg@ibr.cs.tu-bs.de
X-BeenThere: nmrg@ibr.cs.tu-bs.de
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Network Management Research Group <nmrg.ibr.cs.tu-bs.de>
List-Unsubscribe: <https://mail.ibr.cs.tu-bs.de/mailman/listinfo/nmrg>, <mailto:nmrg-request@ibr.cs.tu-bs.de?subject=unsubscribe>
List-Archive: <http://mail.ibr.cs.tu-bs.de/pipermail/nmrg>
List-Post: <mailto:nmrg@ibr.cs.tu-bs.de>
List-Help: <mailto:nmrg-request@ibr.cs.tu-bs.de?subject=help>
List-Subscribe: <https://mail.ibr.cs.tu-bs.de/mailman/listinfo/nmrg>, <mailto:nmrg-request@ibr.cs.tu-bs.de?subject=subscribe>
X-List-Received-Date: Mon, 19 May 2008 18:43:48 -0000

Thanks,
dbh 

> -----Original Message-----
> From: Juergen Schoenwaelder 
> [mailto:j.schoenwaelder@jacobs-university.de] 
> Sent: Monday, May 19, 2008 2:31 PM
> To: David B Harrington
> Cc: 'Karen R. Sollins'; 'Internet Research Steering Group'; 
> nmrg@ibr.cs.tu-bs.de
> Subject: Re: [nmrg] Re: [IRSG] review of 
> draft-irtf-nmrg-snmp-measure-04.txt
> 
> On Mon, May 19, 2008 at 09:15:49AM -0400, David B Harrington wrote:
>  
> > I think something should be said that this information could be
used
> > by an attacker (especially an attacker internal to the
organization)
> > to decide/pinpoint where and how to attack. This information might
> > need to be anonymized, although that would seem to defeat 
> the purpose
> > of having the information. I don't really know what to suggest
here
> > other than to raise the point in the security 
> considerations that such
> > location information might be sensitive, and could aid an
attacker.
> 
> I suggest to add the following text to the end of the security
> considerations:
> 
>    The meta data associated with traces and in particular
information
>    about the organization owning a network and the description of
the
>    measurement point in the network topology where a trace 
> was collected
>    may be misused to decide/pinpoint where and how to attack 
> a network.
>    Meta data therefore needs to be properly protected.
> 
> In addition, I like to replace "generate XML traces" with "generate
> CSV or XML traces" in the first sentence of the second paragraph of
> the security considerations text since the rest of the paragraph
> applies to both trace formats and not just XML.
> 
> /js
> 
> -- 
> Juergen Schoenwaelder           Jacobs University Bremen gGmbH
> Phone: +49 421 200 3587         Campus Ring 1, 28759 Bremen, Germany
> Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>
>