Re: [secdir] secdir review of draft-ietf-tictoc-multi-path-synchronization-05

Tal Mizrahi <talmi@marvell.com> Mon, 19 September 2016 13:24 UTC

Return-Path: <talmi@marvell.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCB8B127735; Mon, 19 Sep 2016 06:24:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AWnrl1zh-F8w; Mon, 19 Sep 2016 06:24:08 -0700 (PDT)
Received: from mx0b-0016f401.pphosted.com (mx0b-0016f401.pphosted.com [67.231.156.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7E72912B029; Mon, 19 Sep 2016 06:24:08 -0700 (PDT)
Received: from pps.filterd (m0045851.ppops.net [127.0.0.1]) by mx0b-0016f401.pphosted.com (8.16.0.17/8.16.0.17) with SMTP id u8JDL8IJ017382; Mon, 19 Sep 2016 06:24:02 -0700
Received: from il-exch02.marvell.com ([199.203.130.102]) by mx0b-0016f401.pphosted.com with ESMTP id 25h5bp0d99-2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Mon, 19 Sep 2016 06:24:01 -0700
Received: from IL-EXCH01.marvell.com (10.4.102.220) by IL-EXCH02.marvell.com (10.4.102.221) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Mon, 19 Sep 2016 16:23:59 +0300
Received: from IL-EXCH01.marvell.com ([fe80::5d63:81cd:31e2:fc36]) by IL-EXCH01.marvell.com ([fe80::5d63:81cd:31e2:fc36%20]) with mapi id 15.00.1104.000; Mon, 19 Sep 2016 16:23:58 +0300
From: Tal Mizrahi <talmi@marvell.com>
To: Ben Laurie <benl@google.com>
Thread-Topic: [secdir] secdir review of draft-ietf-tictoc-multi-path-synchronization-05
Thread-Index: AQHSEeSgVxkDrkl/jE+0/2Rx8wj6kqB/4pcA///YqYCAADiWMIAAgDWAgABXvyA=
Date: Mon, 19 Sep 2016 13:23:57 +0000
Message-ID: <ff13c3a269a84fd8969171109ee8064c@IL-EXCH01.marvell.com>
References: <CACsn0cmCGrpaHtiLNEpnN52_+FqM4XiCtUHhZm9XQD1qfbFH3w@mail.gmail.com> <2c34b139112a45ac9a68ff000aa7d934@IL-EXCH01.marvell.com> <CACsn0ckk0egkREuvfhwU6FJV5LBV4BPs5HsNoRk63yWjVdBB_g@mail.gmail.com> <3993e58a01f4472992ae6fcdfaa8e0f7@IL-EXCH01.marvell.com> <CABrd9STp-VgHoczmQfBoL-MKWFkJARt2Wj6JNpBWaanHf99mdA@mail.gmail.com>
In-Reply-To: <CABrd9STp-VgHoczmQfBoL-MKWFkJARt2Wj6JNpBWaanHf99mdA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [199.203.130.14]
Content-Type: multipart/alternative; boundary="_000_ff13c3a269a84fd8969171109ee8064cILEXCH01marvellcom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2016-09-19_08:, , signatures=0
X-Proofpoint-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1609020000 definitions=main-1609190184
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/8UB_PgH5Oq7c006yqMWrH3d3EBU>
Cc: "Karen ODonoghue \(odonoghue@isoc.org\)" <odonoghue@isoc.org>, "secdir@ietf.org" <secdir@ietf.org>, Suresh Krishnan <suresh.krishnan@ericsson.com>, "draft-ietf-tictoc-multi-path-synchronization.all@tools.ietf.org" <draft-ietf-tictoc-multi-path-synchronization.all@tools.ietf.org>, "<iesg@ietf.org>" <iesg@ietf.org>
Subject: Re: [secdir] secdir review of draft-ietf-tictoc-multi-path-synchronization-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Sep 2016 13:24:12 -0000

Hi Ben,

Just to clarify, we are talking about an attacker that adds a malicious delay that may be as low as, say five microseconds (yes, microseconds) beyond the ‘normal’ path delay. A five microsecond additional delay is certainly enough to kill the protocol in various environments such as mobile base stations or power substations.

Five microseconds is just an example. The point is that the attacker adds some additional delay which is at least an order of magnitude lower than the path delay.

Correct me if I am wrong, but a challenge/response will probably not be effective in detecting delay attacks in this order of magnitude.

Best regards,
Tal.

From: Ben Laurie [mailto:benl@google.com]
Sent: Monday, September 19, 2016 2:01 PM
To: Tal Mizrahi
Cc: Watson Ladd; draft-ietf-tictoc-multi-path-synchronization.all@tools.ietf.org; Karen ODonoghue (odonoghue@isoc.org); <iesg@ietf.org>; Suresh Krishnan; secdir@ietf.org
Subject: Re: [secdir] secdir review of draft-ietf-tictoc-multi-path-synchronization-05


On 19 September 2016 at 01:34, Tal Mizrahi <talmi@marvell.com<mailto:talmi@marvell.com>> wrote:
Time protocols have a pretty unique property: even if you use the strongest cryptographic mechanisms, the protocol can still easily be attacked by a man-in-the-middle who simply adds a constant delay to some of the packets, and thereby easily manipulates the protocol. The only way to mitigate delay attacks is by redundancy: multiple time sources and/or multiple network paths.

Surely not - challenge/response, for example, would also reveal a delay.