[OPSEC] Security Assessment of the Transmission Control Protocol (TCP)

Fernando Gont <fernando@gont.com.ar> Sat, 21 February 2009 23:37 UTC

Return-Path: <fernando@gont.com.ar>
X-Original-To: opsec@core3.amsl.com
Delivered-To: opsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0B4273A6831; Sat, 21 Feb 2009 15:37:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.437
X-Spam-Level:
X-Spam-Status: No, score=-1.437 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_NET=0.611, RCVD_IN_DNSWL_LOW=-1, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7mRl6x-T1-k6; Sat, 21 Feb 2009 15:37:16 -0800 (PST)
Received: from smtp1.xmundo.net (unknown [201.216.232.80]) by core3.amsl.com (Postfix) with ESMTP id C305A3A677D; Sat, 21 Feb 2009 15:37:14 -0800 (PST)
Received: from venus.xmundo.net (venus.xmundo.net [201.216.232.56]) by smtp1.xmundo.net (Postfix) with ESMTP id 4A7206B6576; Sat, 21 Feb 2009 20:37:34 -0300 (ART)
Received: from [192.168.0.106] (131-131-17-190.fibertel.com.ar [190.17.131.131]) (authenticated bits=0) by venus.xmundo.net (8.14.1/8.14.1) with ESMTP id n1LNbAXl004163; Sat, 21 Feb 2009 21:37:14 -0200
Message-ID: <49A0902B.2030906@gont.com.ar>
Date: Sat, 21 Feb 2009 21:37:15 -0200
From: Fernando Gont <fernando@gont.com.ar>
User-Agent: Thunderbird 2.0.0.19 (X11/20090105)
MIME-Version: 1.0
To: opsec@ietf.org, tcpm@ietf.org
X-Enigmail-Version: 0.95.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Greylist: Sender succeeded SMTP AUTH authentication, not delayed by milter-greylist-3.0 (venus.xmundo.net [201.216.232.56]); Sat, 21 Feb 2009 20:37:31 -0300 (ART)
Subject: [OPSEC] Security Assessment of the Transmission Control Protocol (TCP)
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 21 Feb 2009 23:37:18 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello, folks,

Last week the UK CPNI (United Kingdom's Centre for the Protection of
National Infrastructure) released the document "Security Assessment of
the Transmission Control Protocol (TCP)". The document analyzes the
relevant specifications from a security point of view, and also analyzes
  the implications of some implementation strategies taken by popular
TCP implementations. This document is available at:
http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf

As part of the same project, we have produced an IETF I-D version of the
UK CPNI document, in the hope that the IETF works on this stuff and
hopefully publishes some version of the aforementioned document. The
resulting IETF I-D is entitled "Security Assessment of the Transmission
Control Protocol (TCP)" (draft-gont-tcp-security-00.txt) and is
available at: http://tools.ietf.org/id/draft-gont-tcp-security-00.txt

Any comments will be more than welcome.

Thanks!

Kind regards,
- --
Fernando Gont
e-mail: fernando@gont.com.ar || fgont@acm.org
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1





-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQEcBAEBCAAGBQJJoJAhAAoJEJbuqe/Qdv/x7AEIAKBKZUtyWYG3RZ3yYYty37wl
ytw6eMKkKBk61Z6F41bVUzz6trgpHN80/m0DrwLSOCGKJjTaUJZ3ksCumD7ougjp
BR5k5q90Tn2xFGpMOURvTwotmo+LDK+sR6VVDa0Tv5iIaWL2Daz91kLa/7aJCi8t
TpABuCfAQ+VW08muA0nRM7CF2e1bgxSrwFp77xFkx7Sb8jCi9/L/Mk/lclg9Fzob
+8kQNHMElXq1IsUAwDHfouE20MhEPVUDgqoyt0T+BHwCijdgu+QpIrnhioROIhd4
BauCRmEgFLymuodOjjpQOPt9/g1dF8Hvma6+wRIRz53F3d6HXHuql3T3CfP485Y=
=UKKW
-----END PGP SIGNATURE-----