[Sidrops] Re: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024)
Amir Herzberg <amir.lists@gmail.com> Mon, 27 May 2024 03:05 UTC
Return-Path: <amir.herzberg@gmail.com>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DD1D4C15109C for <sidrops@ietfa.amsl.com>; Sun, 26 May 2024 20:05:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ab8AyUxZeEmu for <sidrops@ietfa.amsl.com>; Sun, 26 May 2024 20:05:54 -0700 (PDT)
Received: from mail-wr1-x42d.google.com (mail-wr1-x42d.google.com [IPv6:2a00:1450:4864:20::42d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 15236C14F602 for <sidrops@ietf.org>; Sun, 26 May 2024 20:05:54 -0700 (PDT)
Received: by mail-wr1-x42d.google.com with SMTP id ffacd0b85a97d-357f1c0b86fso851650f8f.0 for <sidrops@ietf.org>; Sun, 26 May 2024 20:05:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1716779152; x=1717383952; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=SZptbU+ogE+SV71rjxaK9aJi6h6GQZuliUeagiG2aLo=; b=mtpU1XKzqy1v5kI1Bulpy60VOxnkjZWAiygSHuxzac2ZutnX/KE2EH605u2NPunBEP IVQ9GEF8YivFkuo11ynun5MyQlvsxYf3RZCr+tZFM731Fic72jby06WhGxbgPG+3gpOw UrxGvi1qjZNfCJB7V6MK4VbBNUQk5seoA67Ls4z/lhSeHNFJq+s6mJrc/1yfG5z0DxHO amFXIMoaMWoRTWfEGVdyd32QjheCXtbH4bF9V8/E6PhyvL0xlRRrcYUi9b/kibs5WtWw p3wzqzYQgke/IcPqXrlhivFz1XhN51bKBgSlL9+ZEpe0jnhwctsKlDPEWQINZ5v1zlBM sxqA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1716779152; x=1717383952; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=SZptbU+ogE+SV71rjxaK9aJi6h6GQZuliUeagiG2aLo=; b=PulSFx99ROw8MJDQ8qoSWjliPqqNSFE32ukgkDIT2gWOehjOkEY4P+JyRqudf11IIh Ar47S0WBZxam7dZc/3mPE4cGnNdAKvoQqVtrk4WFkT2vFt0aV0J7yRc1PktpsHMGv9JN MdBQJQlE+qu0dzf1iM/ERpFs85Fc6b6vXnpXSsJC5Hvd3zN8rCzaH0xaBr4rXKnkH/K1 2dtyk99nnvduUF3gdKXYlnmCcUL0Z3Ftppw//nu1lhqRKR9j0f9TUZnP1a1SIWcCe0Zy 29XYlTaNIcAtWjD9YNrJNr1IbpwESiFQgL4+KdKoVAnCfEAcykxDyS9FtXdcOmL01qx3 n5rg==
X-Gm-Message-State: AOJu0YyBWt1iv38NgrKip4ZbDbUZ+LoKd0RzHOVxXL61VaANRKMa5JlG myxOBcGTRjGwnhMP83DjTSXNpTWqUSYpFKaQSnEp0vtGAZ1+L8XpHKdE0v0K5fegmy9Gqbl5wv9 sDcJo/sOYlX9hzFb1ZotkK9WkXqucyYj3
X-Google-Smtp-Source: AGHT+IHfYa2Ax51yu7hjUcg7J1fTco+m54BtisTi5Js/lDZI5OnVMOFW4EyLo6g/kLUOIqe+4HEHJOMHwHiWvz6/FKY=
X-Received: by 2002:a5d:4ec3:0:b0:351:ce05:7a30 with SMTP id ffacd0b85a97d-3552fdf23aemr5831265f8f.52.1716779151869; Sun, 26 May 2024 20:05:51 -0700 (PDT)
MIME-Version: 1.0
From: Amir Herzberg <amir.lists@gmail.com>
Date: Sun, 26 May 2024 23:05:40 -0400
Message-ID: <CAHBw0M8nDgvykcy=d=U0H1ATW_Q4YG1CiW6c6DJ9ae87qeertA@mail.gmail.com>
To: sidrops@ietf.org
Content-Type: multipart/alternative; boundary="00000000000081504d061966cb8a"
Message-ID-Hash: PQJTRPJTGHYJ3F7O5O2WEWRW55MRDGCK
X-Message-ID-Hash: PQJTRPJTGHYJ3F7O5O2WEWRW55MRDGCK
X-MailFrom: amir.herzberg@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Sidrops] Re: WG Adoption call for draft-sriram-sidrops-spl-verification - ENDS 06/03/2024 (June 3 2024)
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/ZUHS60_ZbG0d--daabSN3UzXi7Q>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>
I've read the draft and have the following comments. 1. I think the draft doesn't clearly distinguish between (intentional) attacks and unintentional misconfigurations. I think that the authors really meant, mostly or always, to prevent unintentional misconfigurations, in which case, their use of the term `attack' is confusing. Changing the term should be easy. 2. An exception is the 4th reason, i.e., when a prefix owner publishes ROA for AS 7 and some prefix 1.2.3/24 but AS 7 doesn't announce 1.2.3/24. In this case, attacker could do origin hijack of 1.2.3/24 by announcing it with origin AS 7 (and itself as the next AS). I understand the motivation of supporting direct server return (DSR) using BAR-SAV, where we want a ROA to exist without announcing the prefix. However, is SPV the best mechanism to deal with this? I think a better alternative would be an extension to the ROA mechanism. This extension will define a `conditional ROA'. This conditional ROA will also contain the result of a hash function h(x) over some random x. You can use the conditional ROA in two ways: - without the preimage x: such ROA will not make announcements for AS 7 and 1.2.3/24 valid. However, it could be used to allow DSR , i.e., it would be considered for BAR-SAV filtering. - with the preimage x, provided as a transitive BGP attribute or otherwise: this turns the conditional ROA into regular ROA. best, Amir -- Amir Herzberg Comcast professor of Security Innovations, Computer Science and Engineering, University of Connecticut Homepage: https://sites.google.com/site/amirherzberg/home `Applied Introduction to Cryptography and Cybersecurity' textbook: https://sites.google.com/site/amirherzberg/crypto-cyber-book
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Keyur Patel
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Lubashev, Igor
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Borchert, Oliver (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Lancheng Qin
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Amir Herzberg
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Tim Bruijnzeels
- [Sidrops] Re: WG Adoption call for draft-sriram-s… junzhang
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… gengnan
- [Sidrops] Re: WG Adoption call for draft-sriram-s… gengnan
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Libin Liu
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Yangyang Wang
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Sriram, Kotikalapudi (Fed)
- [Sidrops] Re: Closed - WG Adoption call for draft… Keyur Patel
- [Sidrops] Re: WG Adoption call for draft-sriram-s… Ties de Kock