Return-Path: <ramakrishnadtv@nivettisystems.com>
X-Original-To: ospf@ietfa.amsl.com
Delivered-To: ospf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id C4E4912D679
 for <ospf@ietfa.amsl.com>; Wed, 11 May 2016 21:49:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=netorg676131.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id euF9k24QzXkN for <ospf@ietfa.amsl.com>;
 Wed, 11 May 2016 21:49:04 -0700 (PDT)
Received: from APC01-HK2-obe.outbound.protection.outlook.com
 (mail-hk2apc01on0110.outbound.protection.outlook.com [104.47.124.110])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 1C92212D0DD
 for <ospf@ietf.org>; Wed, 11 May 2016 21:49:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=NETORG676131.onmicrosoft.com; s=selector1-nivettisystems-com;
 h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version;
 bh=6sqqEb71bYqDF/0cEUde6D2f+/ZG9XNLDBQwqJst2xA=;
 b=Ythu352CU+yhD5wdolOnCPTYJZ4OK8/GbVCj4T/J5hh/G9w5D+VNmTJw7ww1aF2u/5Aq/eNgQCgJjiW3gdthVlkJJQGO1VoJKtrwL3IMvRX2tmWGDNZeZ81RYVjNQG7w9NcPZ8czJPcJ20g0B/9aHPY2E0kFSBxHzS2v18iU0oY=
Received: from KL1PR0401MB1544.apcprd04.prod.outlook.com (10.165.249.158) by
 KL1PR04MB1606.apcprd04.prod.outlook.com (10.167.61.28) with Microsoft SMTP
 Server (TLS) id 15.1.492.11; Thu, 12 May 2016 04:49:00 +0000
Received: from KL1PR0401MB1544.apcprd04.prod.outlook.com ([10.165.249.158]) by
 KL1PR0401MB1544.apcprd04.prod.outlook.com ([10.165.249.158]) with
 mapi id 15.01.0492.016; Thu, 12 May 2016 04:48:59 +0000
From: Ramakrishna DTV <ramakrishnadtv@nivettisystems.com>
To: Manav Bhatia <manavbhatia@gmail.com>
Thread-Topic: [OSPF] Fw: New Version Notification for
 draft-manjuldtv-ospf-sequence-number-00.txt
Thread-Index: AQHRq5iDI45ZmPCOekqfeZl/Lp+NDp+0k8d6gAAWyICAABC5kQ==
Date: Thu, 12 May 2016 04:48:59 +0000
Message-ID: <KL1PR0401MB1544349FCF40E95494CC1D4EA3730@KL1PR0401MB1544.apcprd04.prod.outlook.com>
References: <D358C4E4.607A9%acee@cisco.com>
 <KL1PR0401MB1544944FE1E375A8FB7A31C0A3730@KL1PR0401MB1544.apcprd04.prod.outlook.com>,
 <CAG1kdoiyj_s_gzHibrmomPJAZo28bCLDxqPRnbeS6-ooJzb_MQ@mail.gmail.com>
In-Reply-To: <CAG1kdoiyj_s_gzHibrmomPJAZo28bCLDxqPRnbeS6-ooJzb_MQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: cisco.com; dkim=none (message not signed)
 header.d=none;cisco.com; dmarc=none action=none
 header.from=nivettisystems.com;
x-originating-ip: [25.169.49.132]
x-ms-office365-filtering-correlation-id: ac24acd0-1281-4e3e-8310-08d37a20bbe7
x-microsoft-exchange-diagnostics: 1; KL1PR04MB1606;
 5:SQ+/HHb3vK6AMJSbs0/VeZl0ThncOyY3sqioRlex2NekZHI44XfCs4WxKNLIIFazGVlz9QAQM6Y6Fw3NDcSoiH0GuJMfplgmAN4nzqNOTcT4rkjhno3Nipx5hoCV2LCkdefqPrKnOC7ETXc08ucYww==;
 24:SsVOBlT1jco/k0TaqmL8IjauX7Fj3N2wXBsaadNIJsvsDBcGY97qDNOiyT8DslM50stsqTb/bKxdjxh+fzTBR3QPbDJnQOjrEBqkSGqE+wM=;
 7:egpO0QE8fQHnnBcyvnXmIOVfV6VT8D7gFK9e1/OWShqfDhq52Yt3JI4ChbpLO5xE7MMULx0cmt9KJouCMZ8gTV7RL7sTjkRVAWfzfDPOmatwretLkEr/pTuw5Lclm1xXhQ2W99qFFsjznWm+PzGSSMECsGHwAnVGWt38kmQe1YxA+d1MyMgH2eoOHJZqMAda
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:KL1PR04MB1606;
x-microsoft-antispam-prvs: <KL1PR04MB160688AE52C6FC350A330433A3730@KL1PR04MB1606.apcprd04.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(95692535739014);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0;
 RULEID:(6040130)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(6041072)(6043046);
 SRVR:KL1PR04MB1606; BCL:0; PCL:0; RULEID:; SRVR:KL1PR04MB1606; 
x-forefront-prvs: 0940A19703
x-forefront-antispam-report: SFV:NSPM;
 SFS:(10019020)(51884002)(24454002)(377424004)(377454003)(3660700001)(122556002)(10400500002)(77096005)(14971765001)(92566002)(87936001)(19580395003)(19580405001)(3900700001)(5002640100001)(66066001)(33656002)(86362001)(19625215002)(5004730100002)(74316001)(16236675004)(76176999)(50986999)(54356999)(10710500007)(19617315012)(3280700002)(4326007)(5008740100001)(1220700001)(16601075003)(2420400007)(9686002)(6116002)(586003)(102836003)(5003600100002)(3846002)(110136002)(106116001)(2950100001)(2900100001)(189998001)(19627405001)(76576001)(7110500001)(345774005)(15650500001)(15975445007)(2906002)(8936002)(230783001)(81166006);
 DIR:OUT; SFP:1102; SCL:1; SRVR:KL1PR04MB1606;
 H:KL1PR0401MB1544.apcprd04.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative;
 boundary="_000_KL1PR0401MB1544349FCF40E95494CC1D4EA3730KL1PR0401MB1544_"
MIME-Version: 1.0
X-OriginatorOrg: nivettisystems.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 May 2016 04:48:59.7394 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 68b780cc-c0fe-4e87-8da2-4702ecb31b90
X-MS-Exchange-Transport-CrossTenantHeadersStamped: KL1PR04MB1606
Archived-At: <http://mailarchive.ietf.org/arch/msg/ospf/LdeRnQBYJK7nxcFqCRbSxm5NB8M>
Cc: "ospf@ietf.org" <ospf@ietf.org>,
 Manjul Khandelwal <manjul@nivettisystems.com>
Subject: Re: [OSPF] Fw: New Version Notification for
 draft-manjuldtv-ospf-sequence-number-00.txt
X-BeenThere: ospf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: The Official IETF OSPG WG Mailing List <ospf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ospf>,
 <mailto:ospf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ospf/>
List-Post: <mailto:ospf@ietf.org>
List-Help: <mailto:ospf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ospf>,
 <mailto:ospf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 May 2016 04:49:08 -0000

--_000_KL1PR0401MB1544349FCF40E95494CC1D4EA3730KL1PR0401MB1544_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Manav,

Thank you for your comments.

Gabi has published multiple attacks against OSPF.

The attack we are targeting is published in

@inproceedings{nakibly2012persistent,
  title=3D{Persistent OSPF Attacks.},
  author=3D{Nakibly, Gabi and Kirshon, Alex and Gonikman, Dima and Boneh, D=
an},
  booktitle=3D{NDSS},
  year=3D{2012}
}

This attack indeed depends on predictability of sequence numbers.
On a side note, we even verified that fact with Gabi Nakibly himself
over a private mail.

The attack you are discussing in your article is a different attack.
It was described by Gabi in great detail in a different paper:

@inproceedings{nakibly2014ospf,
  title=3D{OSPF vulnerability to persistent poisoning attacks: a systematic=
 analysis},
  author=3D{Nakibly, Gabi and Sosnovich, Adi and Menahem, Eitan and Waizel,=
 Ariel and Elovici, Yuval},
  booktitle=3D{Proceedings of the 30th Annual Computer Security Application=
s Conference},
  pages=3D{336--345},
  year=3D{2014},
  organization=3D{ACM}
}

As you rightly mentioned, this attack does not depend upon sequence number
predictability. But our draft is *not* targeting *this* attack.

Thanks and regards,
Ramakrishna DTV.


________________________________
From: Manav Bhatia <manavbhatia@gmail.com>
Sent: Thursday, May 12, 2016 9:16 AM
To: Ramakrishna DTV
Cc: Acee Lindem (acee); Manjul Khandelwal; ospf@ietf.org
Subject: Re: [OSPF] Fw: New Version Notification for draft-manjuldtv-ospf-s=
equence-number-00.txt

Hi DTV,

I dont agree to your assessment of how the attack evades the "natural fight=
-back mechanism" in OSPF.

Its got *nothing* to do with the sequence numbers being predictable, etc. I=
 have explained in depth how the Gaby attack works here:

https://routingfreak.wordpress.com/2013/09/09/how-bad-is-the-ospf-vulnerabi=
lity-exposed-by-black-hat/
How bad is the OSPF vulnerability exposed by Black Hat ...<https://routingf=
reak.wordpress.com/2013/09/09/how-bad-is-the-ospf-vulnerability-exposed-by-=
black-hat/>
routingfreak.wordpress.com
I was asked a few weeks ago by our field engineers to provide a fix for the=
 OSPF vulnerability exposed by Black Hat last month. Prima facie there appe=
ared ...



Clipped from the blog:

"This attack exploits a potential omission (or a bug if you will) in the st=
andard where it does not mandate that the receiving router verifies that th=
e Link State ID and the Advertising Router fields in the Router LSA are the=
 exact same value.

This attack sends malacious Router LSAs with two different values in the LS=
 header. The Link State ID carries the Router ID of the router that is bein=
g attacked (the victim) and the Advertising Router is set to some different=
 (any) value.

When the victim receives the malacious Router LSA, it does not refresh this=
 LSA as it doesnt recognize this as its own self generated LSA. This is bec=
ause the OSPF spec clearly says in Sec 13.4 that =93A self-originated LSA i=
s detected when either 1) The LSA=92s Advertising Router is equal to the ro=
uter=92s own Router ID or 2) the LSA is a network LSA .. =93.

This means that OSPF=92s natural fight back mechanism is NOT triggered by t=
he victim router as long as the field =91Advertising Router=92 of a LSA is =
NOT equal to the victim=92s Router ID. This is true even if the =91Link Sta=
te ID=92 of that LSA is equal to the victim=92s Router ID. Going further it=
 means no LSA refresh is triggered even if the malacious LSA claims to desc=
ribe the links of the victim router!"

I describe further in the blog that not all router implementations are susc=
eptible to the attack. Its dependent on how the LSA is picked up from the L=
SDB.

Cheers, Manav

On Thu, May 12, 2016 at 7:59 AM, Ramakrishna DTV <ramakrishnadtv@nivettisys=
tems.com<mailto:ramakrishnadtv@nivettisystems.com>> wrote:
Hi Acee,

We currently provided the following description of this attack in the draft=
:

 "The paper refers to the attack as "Disguised LSA" and is of
   persistent nature.  This attack is launched from a compromised router
   inside a routing domain.  In this attack, the compromised router
   alters the LSA of an uncompromised router (victim).  Normally, such
   an attempt does not have persistence because the victim generates a
   new LSA when it sees such self-originated LSAs (referred to as
   "fight-back" mechanism in the paper).  But the paper makes disguised
   LSA persistent because all the fields { LS sequence number, checksum}
   are predictable.  It alters the existing LSA of victim to suit its
   needs but sets the sequence number to +1 of the existing LSA and
   alters the LSA so that checksum matches with checksum that would be
   generated by the victim when it generates the new LSA.  When this
   disguised LSA reaches the victim, it does not fight back because it
   compares only the fields { LS sequence number, checksum, age} to
   check for duplicates and not the actual content of LSA.

   This attack enables an insider attacker to fully control the entire
   content of an LSA.  We think this attack is powerful."

These details are currently present in Section 4, which is titled "Implemen=
tation advice".
We can probably move it to a different section (e.g., "Introduction") to ma=
ke it clear.

If you think even more additional details about the attack are useful to th=
e working group,
please let us know. We will add.

Thank you.

Regards,
Ramakrishna DTV.


________________________________________
From: Acee Lindem (acee) <acee@cisco.com<mailto:acee@cisco.com>>
Sent: Wednesday, May 11, 2016 8:49 PM
To: Manjul Khandelwal; ospf@ietf.org<mailto:ospf@ietf.org>
Cc: Ramakrishna DTV
Subject: Re: [OSPF] Fw: New Version Notification for draft-manjuldtv-ospf-s=
equence-number-00.txt

Hi Manjul,

Would it be possible to succinctly describe these =93certain security
attacks=94 in the draft rather than expecting everyone to read the
referenced paper?

Thanks,
Acee

On 5/11/16, 10:19 AM, "OSPF on behalf of Manjul Khandelwal"
<ospf-bounces@ietf.org<mailto:ospf-bounces@ietf.org> on behalf of manjul@ni=
vettisystems.com<mailto:manjul@nivettisystems.com>> wrote:

>Hi,
>
>We have recently submitted a draft which deals with OSPF LS sequence
>number
>generation mechanism.
>
>Abstract of the draft:
>   The mechanism for LS sequence number generation as specified in RFC
>   2328 and RFC 5340 is completely predictable.  This makes it prone to
>   certain security attacks which exploit the predictable nature of LS
>   sequence numbers.  This draft updates the RFC 2328 to make LS
>   sequence number generation an implementation choice rather than a
>   fixed increment by 1 for successive LSAs.
>
>https://datatracker.ietf.org/doc/draft-manjuldtv-ospf-sequence-number/
>
>We solicit feedback/comments on the draft and request for adoption by the
>OSPF working group.
>
>Regards,
>Manjul Khandelwal
>DTV Ramakrishna Rao
>________________________________________
>From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> <internet-=
drafts@ietf.org<mailto:internet-drafts@ietf.org>>
>Sent: Monday, May 9, 2016 7:22 PM
>To: Manjul Khandelwal; Ramakrishna DTV
>Subject: New Version Notification for
>draft-manjuldtv-ospf-sequence-number-00.txt
>
>A new version of I-D, draft-manjuldtv-ospf-sequence-number-00.txt
>has been successfully submitted by Manjul Khandelwal and posted to the
>IETF repository.
>
>Name:           draft-manjuldtv-ospf-sequence-number
>Revision:       00
>Title:          OSPF LSA sequence number generation
>Document date:  2016-05-09
>Group:          Individual Submission
>Pages:          10
>URL:
>https://www.ietf.org/internet-drafts/draft-manjuldtv-ospf-sequence-number-
>00.txt
>Status:
>https://datatracker.ietf.org/doc/draft-manjuldtv-ospf-sequence-number/
>Htmlized:
>https://tools.ietf.org/html/draft-manjuldtv-ospf-sequence-number-00
>
>
>Abstract:
>   The mechanism for LS sequence number generation as specified in RFC
>   2328 and RFC 5340 is completely predictable.  This makes it prone to
>   certain security attacks which exploit the predictable nature of LS
>   sequence numbers.  This draft updates the RFC 2328 to make LS
>   sequence number generation an implementation choice rather than a
>   fixed increment by 1 for successive LSAs.
>
>
>
>
>Please note that it may take a couple of minutes from the time of
>submission
>until the htmlized version and diff are available at tools.ietf.org<http:/=
/tools.ietf.org>.
>
>The IETF Secretariat
>
>_______________________________________________
>OSPF mailing list
>OSPF@ietf.org<mailto:OSPF@ietf.org>
>https://www.ietf.org/mailman/listinfo/ospf

_______________________________________________
OSPF mailing list
OSPF@ietf.org<mailto:OSPF@ietf.org>
https://www.ietf.org/mailman/listinfo/ospf


--_000_KL1PR0401MB1544349FCF40E95494CC1D4EA3730KL1PR0401MB1544_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi=
n-bottom:0;} --></style>
</head>
<body dir=3D"ltr">
<div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt;color:#000000;back=
ground-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p></p>
<div>Hi Manav,<br>
<br>
Thank you for your comments.<br>
<br>
Gabi has published multiple attacks against OSPF.<br>
<br>
The attack we are targeting is published in<br>
<br>
@inproceedings{nakibly2012persistent,<br>
&nbsp; title=3D{Persistent OSPF Attacks.},<br>
&nbsp; author=3D{Nakibly, Gabi and Kirshon, Alex and Gonikman, Dima and Bon=
eh, Dan},<br>
&nbsp; booktitle=3D{NDSS},<br>
&nbsp; year=3D{2012}<br>
}<br>
<br>
This attack indeed depends on predictability of sequence numbers.<br>
On a side note, we even verified that fact with Gabi Nakibly himself<br>
over a private mail.<br>
<br>
The attack you are discussing in your article is a different attack.<br>
It was described by Gabi in great detail in a different paper:<br>
<br>
@inproceedings{nakibly2014ospf,<br>
&nbsp; title=3D{OSPF vulnerability to persistent poisoning attacks: a syste=
matic analysis},<br>
&nbsp; author=3D{Nakibly, Gabi and Sosnovich, Adi and Menahem, Eitan and Wa=
izel, Ariel and Elovici, Yuval},<br>
&nbsp; booktitle=3D{Proceedings of the 30th Annual Computer Security Applic=
ations Conference},<br>
&nbsp; pages=3D{336--345},<br>
&nbsp; year=3D{2014},<br>
&nbsp; organization=3D{ACM}<br>
}<br>
<br>
As you rightly mentioned, this attack does not depend upon sequence number<=
br>
predictability. But our draft is *not* targeting *this* attack.<br>
<br>
Thanks and regards,<br>
Ramakrishna DTV.<br>
</div>
<p></p>
<br>
<br>
<div style=3D"color: rgb(0, 0, 0);">
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font style=3D"font-size:11pt" color=
=3D"#000000" face=3D"Calibri, sans-serif"><b>From:</b> Manav Bhatia &lt;man=
avbhatia@gmail.com&gt;<br>
<b>Sent:</b> Thursday, May 12, 2016 9:16 AM<br>
<b>To:</b> Ramakrishna DTV<br>
<b>Cc:</b> Acee Lindem (acee); Manjul Khandelwal; ospf@ietf.org<br>
<b>Subject:</b> Re: [OSPF] Fw: New Version Notification for draft-manjuldtv=
-ospf-sequence-number-00.txt</font>
<div>&nbsp;</div>
</div>
<div>
<div dir=3D"ltr">Hi DTV,
<div><br>
</div>
<div>I dont agree to your assessment of how the attack evades the &quot;nat=
ural fight-back mechanism&quot; in OSPF.&nbsp;</div>
<div><br>
</div>
<div>Its got *nothing* to do with the sequence numbers being predictable, e=
tc. I have explained in depth how the Gaby attack works here:</div>
<div><br>
</div>
<div><a id=3D"LPlnk916926" href=3D"https://routingfreak.wordpress.com/2013/=
09/09/how-bad-is-the-ospf-vulnerability-exposed-by-black-hat/">https://rout=
ingfreak.wordpress.com/2013/09/09/how-bad-is-the-ospf-vulnerability-exposed=
-by-black-hat/</a>
<div style=3D"margin-bottom: 20px; overflow: auto; width: 100%; text-indent=
: 0px;" id=3D"LPBorder_GT_14630284860450.4193721834222379">
<table style=3D"width: 90%; background-color: rgb(255, 255, 255); position:=
 relative; overflow: auto; padding-top: 20px; padding-bottom: 20px; margin-=
top: 20px; border-top: 1px dotted rgb(200, 200, 200); border-bottom: 1px do=
tted rgb(200, 200, 200);" id=3D"LPContainer_14630284860420.984788785270969"=
 cellspacing=3D"0">
<tbody>
<tr style=3D"border-spacing: 0px;" valign=3D"top">
<td colspan=3D"2" style=3D"vertical-align: top; position: relative; padding=
: 0px; display: table-cell;" id=3D"TextCell_14630284860430.1049928044319359=
3">
<div id=3D"LPRemovePreviewContainer_14630284860430.8245376642934197"></div>
<div style=3D"top: 0px; color: rgb(0, 120, 215); font-weight: 400; font-siz=
e: 21px; font-family: &quot;wf_segoe-ui_light&quot;,&quot;Segoe UI Light&qu=
ot;,&quot;Segoe WP Light&quot;,&quot;Segoe UI&quot;,&quot;Segoe WP&quot;,Ta=
homa,Arial,sans-serif; line-height: 21px;" id=3D"LPTitle_14630284860440.913=
310187346935">
<a target=3D"_blank" href=3D"https://routingfreak.wordpress.com/2013/09/09/=
how-bad-is-the-ospf-vulnerability-exposed-by-black-hat/" style=3D"text-deco=
ration: none;" id=3D"LPUrlAnchor_14630284860440.9330636516470185">How bad i=
s the OSPF vulnerability exposed by Black
 Hat ...</a></div>
<div style=3D"margin: 10px 0px 16px; color: rgb(102, 102, 102); font-weight=
: 400; font-family: &quot;wf_segoe-ui_normal&quot;,&quot;Segoe UI&quot;,&qu=
ot;Segoe WP&quot;,Tahoma,Arial,sans-serif; font-size: 14px; line-height: 14=
px;" id=3D"LPMetadata_14630284860440.3818672868904276">
routingfreak.wordpress.com</div>
<div style=3D"display: block; color: rgb(102, 102, 102); font-weight: 400; =
font-family: &quot;wf_segoe-ui_normal&quot;,&quot;Segoe UI&quot;,&quot;Sego=
e WP&quot;,Tahoma,Arial,sans-serif; font-size: 14px; line-height: 20px; max=
-height: 100px; overflow: hidden;" id=3D"LPDescription_14630284860450.93247=
80566741263">
I was asked a few weeks ago by our field engineers to provide a fix for the=
 OSPF vulnerability exposed by Black Hat last month. Prima facie there appe=
ared ...</div>
</td>
</tr>
</tbody>
</table>
</div>
<br>
</div>
<div><br>
</div>
<div>Clipped from the blog:</div>
<div><br>
&quot;This attack exploits a potential omission (or a bug if you will) in t=
he standard where it does not mandate that the receiving router verifies th=
at the Link State ID and the Advertising Router fields in the Router LSA ar=
e the exact same value.<br>
<br>
This attack sends malacious Router LSAs with two different values in the LS=
 header. The Link State ID carries the Router ID of the router that is bein=
g attacked (the victim) and the Advertising Router is set to some different=
 (any) value.<br>
<br>
When the victim receives the malacious Router LSA, it does not refresh this=
 LSA as it doesnt recognize this as its own&nbsp;self generated LSA. This i=
s because the OSPF spec clearly says in Sec 13.4 that =93A self-originated =
LSA is detected when either 1) The LSA=92s
 Advertising Router is equal to the router=92s own Router ID or 2) the LSA =
is a network LSA .. =93.<br>
</div>
<br>
This means that OSPF=92s natural fight back mechanism is NOT triggered by t=
he victim router as long as the field =91Advertising Router=92 of a LSA is =
NOT equal to the victim=92s Router ID. This is true even if the =91Link Sta=
te ID=92 of that LSA is equal to the victim=92s
 Router ID. Going further it means no LSA refresh is triggered even if the =
malacious LSA claims to describe the links of the victim router!&quot;
<div><br>
</div>
<div>I describe further in the blog that not all router implementations are=
 susceptible to the attack. Its dependent on how the LSA is picked up from =
the LSDB.&nbsp;</div>
<div><br>
</div>
<div>Cheers, Manav</div>
</div>
<div class=3D"gmail_extra"><br>
<div class=3D"gmail_quote">On Thu, May 12, 2016 at 7:59 AM, Ramakrishna DTV=
 <span dir=3D"ltr">
&lt;<a href=3D"mailto:ramakrishnadtv@nivettisystems.com" target=3D"_blank">=
ramakrishnadtv@nivettisystems.com</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex; border-left:1=
px #ccc solid; padding-left:1ex">
Hi Acee,<br>
<br>
We currently provided the following description of this attack in the draft=
:<br>
<br>
&nbsp;&quot;The paper refers to the attack as &quot;Disguised LSA&quot; and=
 is of<br>
&nbsp; &nbsp;persistent nature.&nbsp; This attack is launched from a compro=
mised router<br>
&nbsp; &nbsp;inside a routing domain.&nbsp; In this attack, the compromised=
 router<br>
&nbsp; &nbsp;alters the LSA of an uncompromised router (victim).&nbsp; Norm=
ally, such<br>
&nbsp; &nbsp;an attempt does not have persistence because the victim genera=
tes a<br>
&nbsp; &nbsp;new LSA when it sees such self-originated LSAs (referred to as=
<br>
&nbsp; &nbsp;&quot;fight-back&quot; mechanism in the paper).&nbsp; But the =
paper makes disguised<br>
&nbsp; &nbsp;LSA persistent because all the fields { LS sequence number, ch=
ecksum}<br>
&nbsp; &nbsp;are predictable.&nbsp; It alters the existing LSA of victim to=
 suit its<br>
&nbsp; &nbsp;needs but sets the sequence number to &#43;1 of the existing L=
SA and<br>
&nbsp; &nbsp;alters the LSA so that checksum matches with checksum that wou=
ld be<br>
&nbsp; &nbsp;generated by the victim when it generates the new LSA.&nbsp; W=
hen this<br>
&nbsp; &nbsp;disguised LSA reaches the victim, it does not fight back becau=
se it<br>
&nbsp; &nbsp;compares only the fields { LS sequence number, checksum, age} =
to<br>
&nbsp; &nbsp;check for duplicates and not the actual content of LSA.<br>
<br>
&nbsp; &nbsp;This attack enables an insider attacker to fully control the e=
ntire<br>
&nbsp; &nbsp;content of an LSA.&nbsp; We think this attack is powerful.&quo=
t;<br>
<br>
These details are currently present in Section 4, which is titled &quot;Imp=
lementation advice&quot;.<br>
We can probably move it to a different section (e.g., &quot;Introduction&qu=
ot;) to make it clear.<br>
<br>
If you think even more additional details about the attack are useful to th=
e working group,<br>
please let us know. We will add.<br>
<br>
Thank you.<br>
<br>
Regards,<br>
Ramakrishna DTV.<br>
<br>
<br>
________________________________________<br>
From: Acee Lindem (acee) &lt;<a href=3D"mailto:acee@cisco.com">acee@cisco.c=
om</a>&gt;<br>
Sent: Wednesday, May 11, 2016 8:49 PM<br>
To: Manjul Khandelwal; <a href=3D"mailto:ospf@ietf.org">ospf@ietf.org</a><b=
r>
Cc: Ramakrishna DTV<br>
Subject: Re: [OSPF] Fw: New Version Notification for draft-manjuldtv-ospf-s=
equence-number-00.txt<br>
<div class=3D"HOEnZb">
<div class=3D"h5"><br>
Hi Manjul,<br>
<br>
Would it be possible to succinctly describe these =93certain security<br>
attacks=94 in the draft rather than expecting everyone to read the<br>
referenced paper?<br>
<br>
Thanks,<br>
Acee<br>
<br>
On 5/11/16, 10:19 AM, &quot;OSPF on behalf of Manjul Khandelwal&quot;<br>
&lt;<a href=3D"mailto:ospf-bounces@ietf.org">ospf-bounces@ietf.org</a> on b=
ehalf of <a href=3D"mailto:manjul@nivettisystems.com">
manjul@nivettisystems.com</a>&gt; wrote:<br>
<br>
&gt;Hi,<br>
&gt;<br>
&gt;We have recently submitted a draft which deals with OSPF LS sequence<br=
>
&gt;number<br>
&gt;generation mechanism.<br>
&gt;<br>
&gt;Abstract of the draft:<br>
&gt;&nbsp; &nbsp;The mechanism for LS sequence number generation as specifi=
ed in RFC<br>
&gt;&nbsp; &nbsp;2328 and RFC 5340 is completely predictable.&nbsp; This ma=
kes it prone to<br>
&gt;&nbsp; &nbsp;certain security attacks which exploit the predictable nat=
ure of LS<br>
&gt;&nbsp; &nbsp;sequence numbers.&nbsp; This draft updates the RFC 2328 to=
 make LS<br>
&gt;&nbsp; &nbsp;sequence number generation an implementation choice rather=
 than a<br>
&gt;&nbsp; &nbsp;fixed increment by 1 for successive LSAs.<br>
&gt;<br>
&gt;<a href=3D"https://datatracker.ietf.org/doc/draft-manjuldtv-ospf-sequen=
ce-number/" rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.o=
rg/doc/draft-manjuldtv-ospf-sequence-number/</a><br>
&gt;<br>
&gt;We solicit feedback/comments on the draft and request for adoption by t=
he<br>
&gt;OSPF working group.<br>
&gt;<br>
&gt;Regards,<br>
&gt;Manjul Khandelwal<br>
&gt;DTV Ramakrishna Rao<br>
&gt;________________________________________<br>
&gt;From: <a href=3D"mailto:internet-drafts@ietf.org">internet-drafts@ietf.=
org</a> &lt;<a href=3D"mailto:internet-drafts@ietf.org">internet-drafts@iet=
f.org</a>&gt;<br>
&gt;Sent: Monday, May 9, 2016 7:22 PM<br>
&gt;To: Manjul Khandelwal; Ramakrishna DTV<br>
&gt;Subject: New Version Notification for<br>
&gt;draft-manjuldtv-ospf-sequence-number-00.txt<br>
&gt;<br>
&gt;A new version of I-D, draft-manjuldtv-ospf-sequence-number-00.txt<br>
&gt;has been successfully submitted by Manjul Khandelwal and posted to the<=
br>
&gt;IETF repository.<br>
&gt;<br>
&gt;Name:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;draft-manjuldtv-ospf-sequ=
ence-number<br>
&gt;Revision:&nbsp; &nbsp; &nbsp; &nbsp;00<br>
&gt;Title:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; OSPF LSA sequence number gener=
ation<br>
&gt;Document date:&nbsp; 2016-05-09<br>
&gt;Group:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Individual Submission<br>
&gt;Pages:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10<br>
&gt;URL:<br>
&gt;<a href=3D"https://www.ietf.org/internet-drafts/draft-manjuldtv-ospf-se=
quence-number-" rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/i=
nternet-drafts/draft-manjuldtv-ospf-sequence-number-</a><br>
&gt;00.txt<br>
&gt;Status:<br>
&gt;<a href=3D"https://datatracker.ietf.org/doc/draft-manjuldtv-ospf-sequen=
ce-number/" rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.o=
rg/doc/draft-manjuldtv-ospf-sequence-number/</a><br>
&gt;Htmlized:<br>
&gt;<a href=3D"https://tools.ietf.org/html/draft-manjuldtv-ospf-sequence-nu=
mber-00" rel=3D"noreferrer" target=3D"_blank">https://tools.ietf.org/html/d=
raft-manjuldtv-ospf-sequence-number-00</a><br>
&gt;<br>
&gt;<br>
&gt;Abstract:<br>
&gt;&nbsp; &nbsp;The mechanism for LS sequence number generation as specifi=
ed in RFC<br>
&gt;&nbsp; &nbsp;2328 and RFC 5340 is completely predictable.&nbsp; This ma=
kes it prone to<br>
&gt;&nbsp; &nbsp;certain security attacks which exploit the predictable nat=
ure of LS<br>
&gt;&nbsp; &nbsp;sequence numbers.&nbsp; This draft updates the RFC 2328 to=
 make LS<br>
&gt;&nbsp; &nbsp;sequence number generation an implementation choice rather=
 than a<br>
&gt;&nbsp; &nbsp;fixed increment by 1 for successive LSAs.<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;Please note that it may take a couple of minutes from the time of<br>
&gt;submission<br>
&gt;until the htmlized version and diff are available at <a href=3D"http://=
tools.ietf.org" rel=3D"noreferrer" target=3D"_blank">
tools.ietf.org</a>.<br>
&gt;<br>
&gt;The IETF Secretariat<br>
&gt;<br>
&gt;_______________________________________________<br>
&gt;OSPF mailing list<br>
&gt;<a href=3D"mailto:OSPF@ietf.org">OSPF@ietf.org</a><br>
&gt;<a href=3D"https://www.ietf.org/mailman/listinfo/ospf" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/ospf</a><br>
<br>
_______________________________________________<br>
OSPF mailing list<br>
<a href=3D"mailto:OSPF@ietf.org">OSPF@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ospf" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/listinfo/ospf</a><br>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_KL1PR0401MB1544349FCF40E95494CC1D4EA3730KL1PR0401MB1544_--

