Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)

"Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> Wed, 19 April 2023 22:14 UTC

Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2643C151B2E; Wed, 19 Apr 2023 15:14:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nist.gov
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Kzb1cB2rCOvM; Wed, 19 Apr 2023 15:14:18 -0700 (PDT)
Received: from GCC02-BL0-obe.outbound.protection.outlook.com (mail-bl0gcc02on20711.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d05::711]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DEDAC151B10; Wed, 19 Apr 2023 15:14:17 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NJOyvsmVpkwspWmg4DrxAlcUL+ME4GE4oiqKFwwVzOJFe7mbmFNIHyo1fRJ8FHir1qb86Fol86MoZ+Y7vBck9CsqnnABslRqKKJ1tTzpXRsae1ExLlp94AlmX9otM9dfwHsqVjYqrTtEE4DV31+tJcLQLY9NPVEZ19owfztX4Ik1cGGoQtZ0ZT/cJ9V6Rbe3/6joEenAavv3gOyhfCkuHH/0r7CK5ar9UAih3GyFRC4nIO2TYJHSpm+4aG631bVubv7XsYFrSLQb8XVnvounrnLnO6M23lQXhD+0yJAn+IO4dn2yIa+GzEphz3Dse72bgCFLx9wBfP9T7MrATziygg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=0K04kT82gORm2GGOn60ZknAbBbv7ZUruICcXpYhrYjM=; b=cVSUlL5IbQptXU56g0irca7b2MoA2gup/u6yEbo9jAIjZCHUy/xPAJflPlSTOR6ClV1dNXzX6BelpO6M96r46QSe8F/GvPhGSs//Z9XFj7eTeF6DBCf+rpmNJ4uxpxJgAwhJhaaE036AQGpiMIcpi0p8bpdsgduqnaSW9Vpo9/kf8zmuUgWtR3tzNcFwgphLdEyVczELnm4cE1P3yyvYJeRZxu91pJXXEVRaG0bjhwKXKEkL8OA2yGBPiL8RVVDFxYMNV99Ww8bTyk3QppIJ3Os8IEISOhEZA1VrplgE5MsfQiMkBdRoEHWLe1Q/acbuKEnCjloNmBK1gK5LBrLNPQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nist.gov; dmarc=pass action=none header.from=nist.gov; dkim=pass header.d=nist.gov; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nist.gov; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0K04kT82gORm2GGOn60ZknAbBbv7ZUruICcXpYhrYjM=; b=CRNYV2cXUNMESOQXOgbjecV1mrz5qS62RjkSCrbMvVasgIn81kgUg7GvCst/cs3ticGtTqCpGLi/ZqrBo+tJ5sPcjXtFmRzTrBlULG6s0SLbk0QDtTonYrUnNY02+3QvwAcrHoUAbIkVoBwMShntJaMzRVYG++rexPDDDnbSt/uVY5q8FjY1/tWeg63ltmpMOALdS3Nhs+pL5TbYVgh9v9pYdeKmeaReg04FTPmkmM35c0ytXWlA5v5e/Evlc7f0bbjB+SivNRjXT0lFSDGAQpS9lE03HTYKpuUZNVZq02J0Dwf7wj8BfFciKBJ8GUqUvorfeFIy6eIGmtRHmzYvmQ==
Received: from SA1PR09MB8142.namprd09.prod.outlook.com (2603:10b6:806:171::8) by PH8PR09MB9007.namprd09.prod.outlook.com (2603:10b6:510:180::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6319.22; Wed, 19 Apr 2023 22:14:12 +0000
Received: from SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::226a:790b:a85c:d03e]) by SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::226a:790b:a85c:d03e%6]) with mapi id 15.20.6298.045; Wed, 19 Apr 2023 22:14:12 +0000
From: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
To: "Lubashev, Igor" <ilubashe@akamai.com>, Claudio Jeker <cjeker@diehard.n-r-g.com>
CC: "sidrops@ietf.org" <sidrops@ietf.org>, "draft-ietf-sidrops-aspa-verification@ietf.org" <draft-ietf-sidrops-aspa-verification@ietf.org>, "draft-ietf-sidrops-aspa-profile@ietf.org" <draft-ietf-sidrops-aspa-profile@ietf.org>, "sidrops-chairs@ietf.org" <sidrops-chairs@ietf.org>
Thread-Topic: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)
Thread-Index: AQHZUV6mxB5bPFSj10Ch+S0fYxNY/K77vemAgAuycmCAB0/JAIAA8bzMgAAMfviAAPrBAIAANBelgABAVgCAIkGKEA==
Date: Wed, 19 Apr 2023 22:14:11 +0000
Message-ID: <SA1PR09MB81428936A8B2BC30C04C4B2684629@SA1PR09MB8142.namprd09.prod.outlook.com>
References: <SA1PR09MB814241245D01E81BADE3ED0884CF9@SA1PR09MB8142.namprd09.prod.outlook.com> <31FDE1E9-3E87-4011-B65B-C6B3A264303F@vigilsec.com> <SA1PR09MB81427B4A1B126A5D1C1E289C84CF9@SA1PR09MB8142.namprd09.prod.outlook.com> <SA1PR09MB8142E41F2D6B537BCAA758F384CC9@SA1PR09MB8142.namprd09.prod.outlook.com> <CAL9jLaYz3OhcwBBcVMqnUseBR9J1ZyktcJo5YLeefQHMoYJu+A@mail.gmail.com> <CAL9jLaZ7eDc+zbhapS8dTYQKnTfgLd=MOPYw97-qcJ4eP6S6Mg@mail.gmail.com> <CAL9jLaYJ4ODfumG9Yk3-yv=_TaTSUeD++U4sGy7S-0xWcGBQPw@mail.gmail.com> <ZBGqSVL9sSqnAiJc@diehard.n-r-g.com> <SA1PR09MB8142E9F71F250B83062C724884869@SA1PR09MB8142.namprd09.prod.outlook.com> <ZCGcYHJ9PyrjgR+V@diehard.n-r-g.com> <SA1PR09MB8142EA7F33880679E9B509D384889@SA1PR09MB8142.namprd09.prod.outlook.com> <SA1PR09MB81426E1BB66D6DF31860F26984889@SA1PR09MB8142.namprd09.prod.outlook.com> <ed0146b09da346b2b48cb9701240926c@akamai.com> <SA1PR09MB81427D28EF661F9DAB05FB9B84889@SA1PR09MB8142.namprd09.prod.outlook.com> <c62da49ce2a142999260371a0af7b673@akamai.com>
In-Reply-To: <c62da49ce2a142999260371a0af7b673@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nist.gov;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA1PR09MB8142:EE_|PH8PR09MB9007:EE_
x-ms-office365-filtering-correlation-id: 090a6eb2-ee5f-4b7e-b210-08db41236780
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: +BSTpyMHmJqn12oA48stvwJpvi8Mk5hONXK/sl51P/U2asTM9D+uUKQNXHjBn/o+Beuv/+4YWWhXJihzNWc/mzpHbXvkhrWorcXzjpZrxL+ZymF8s0qHLmojOyMfjZeCWpu6sZU9B730suHvi2ZcDhd+NmrCsjQRnwQYcggdPRa9jcEZgPVOk+prVLXwKgAzk7Qs6QS9lLcHBvZ/yRzM9fFH+ZV7pZyyjIv5Wh6VmOP2iaYQ+cyoDjapXkPYi5gJBfNzitRW2dxwjyDfe5dOludllEqJn6Kq4n5SspesaWnWUKlBgDz5oLhPgZz6ZKLxH82h84QZ7lHZYbxs0tVm4+dfksecC0ptOqvRYgNR18DEc1aMhB0/Ct9bcCSDh1augQC8vbZkkAZutCGPgviCmbN77YxkW5e+Bp1l++qkN2j/MU1kJF76fjpcTM8scg5iXk3JWXphifS7kdsuv1YfPK6K3enh4jvW1OilzrWCfOKr41UJKUpHSSDxIIljbjD8YcNrrPFSYxCY9dhf45DolNiraDLLLFpTMVwZ5QiC5PbvOUwwJ67H7QYulHAS7CeyLAvutM7vQdqWK7/CxwsKW8+i72ivs2hzBXDkn4OrmrM=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR09MB8142.namprd09.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(366004)(451199021)(38070700005)(38100700002)(15650500001)(2906002)(8936002)(8676002)(122000001)(86362001)(66899021)(52536014)(5660300002)(33656002)(7696005)(55016003)(71200400001)(53546011)(9686003)(6506007)(26005)(966005)(54906003)(498600001)(83380400001)(186003)(82960400001)(110136005)(76116006)(66946007)(4326008)(66476007)(66556008)(66446008)(64756008); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 8SxMbJ4zW5igoQRP2aPw6+UN1soCaWRcKMm452OJhOxVQYxZ58o0fi53OA17zIvp/H+5tuF4he4x7BT4K5MgHPKtsG4zxQVDJro5ojRGa+lBIU2cohFX5odFTPbkjPVAVeJqFFr1gf3XipiOEsuIOK48hhDy3A9bWC5WbmhzXrPELh9LS+Nx2L/WJ4zUXVrg3jQQg7PCk+RkFK0TWA456sNAgDDCic6ykMLDqCW6qTCnyLw0ybjATV+pY/tM60zGflKi5hGSFcNZqwnrvHhi+jHBi66NPdOYnAeOclydWQqt1lYSWcV13bfqOeIotFx6X2BvwbZK3CE2liGlaoIn9fUcIryCRSKp2KlY0/JwxZNRQl6sxSHUfE3gfkd8cnqtCcF/QFBW7z+kLqfeqTA6S6x58hdKb+/mLo/hXkQOR3lhw7BV2xuE2tkMPIl79++m58Imux3b39qi9wJsXr7t3FCjghgteNIYNkvL4DpmCtShkBqVcRQ010Vi7/SyjX+OqR40vdous82LyvFeUlRSZRzQMB/FNN/W0NwQ/WXrZPnfzUpTLL7V2EjBm5QjK5W0NhTueUXLusuYD9sW6G9IckU1j0DLosHu4aJxoRmrh88VZaif/Lf84l6h+0/Iejoo1vdQ2251zUq+zbrAR+t0tHXV9z/Yu4MGPZxt5dhcwsx2pUoKfkd/8OZ8o+N6+0/LUlNUVtz7Hl78ILjg7rviLzrxNrw6pqL+nxtIIlbJx0woNLlLkXBZe6p4PtYY8Op+K8dZR2nJrqITa4VtAcwRJ04ZEXca+fVwPbsbfw1VUntqRsHpfpgfNp6Ui5nbRlU1CTv/wavCWfLFSRdAFsf1Dfq/vY3/wTwEOoDdjahvh6MIxj4G0AHI7NtOk+eEXpvf1doiNDBHhtOJch+AQOgDanO2p6Top2DcBSR0szTt60kyE7c2GRHXi9npmTN4DkYiVaN10agNs8/uBlSbK9Sxz7HKlwKOD1I4e8R82/GSLOUfNq7uRYFxs/zL7v0myeYMMsi2u/BvD79EZEdmLjnOp7VY38cq90KlvXV9vk89nIrtoSKx9QnSRSGJhOf8GW+iGnzj5Wt1QvvOJ9YsbJ/X+axqtZ87mkmos6z4Iulk1BReHX4gANuRhEA2eI4BeUscFoThI/UFpIE32vHt9vl27H2wg99086vHq0ow3PL20vI2wmJyX71GnNA/Kb8muTU6mklEoMro896zPh+1QOojaB/WgxtiP97OKR0LGEbcK6gFugQNUxgawGI6/vUWfWNWsqlMRB8W+cf6F7hQOkaG/numUu3bex3KG6In/n6ZABNi5rX5T69gBXw9OvYOT7NU/s2IuGGJRDke8vwa0KPAh/b0odDpr/KWhAt7IcQ/M5HqtA/kqzi70E1GoLsVQ4dJo6+frr3K2ol+420ZxrPOaIkuGYP6ZgAw5UVTeEarsMoqAciF1G/ukK8FBrUDxhTC4WFeoNbBOdfJ+J1C4J1Sz8eAfczbfR9i3anZgZ1RIUjovX2WnxItNXSIWJPl8pfEPTumXW+baOu4Nr/yPAjy9Kl77AH/Xw/yGpKXmOdwHk4=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR09MB8142.namprd09.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 090a6eb2-ee5f-4b7e-b210-08db41236780
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Apr 2023 22:14:11.9179 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR09MB9007
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/fM2U74N56D22gWMjXCRdy48geOE>
Subject: Re: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Apr 2023 22:14:22 -0000

Hi Igor, Claudio, Yangyang, Zhibin, and all,

I just uploaded version-14 of the ASPA verification draft.
https://datatracker.ietf.org/doc/html/draft-ietf-sidrops-aspa-verification
Diff: https://author-tools.ietf.org/iddiff?url1=draft-ietf-sidrops-aspa-verification-13&url2=draft-ietf-sidrops-aspa-verification-14&difftype=--html 

This revision (v-14) takes into consideration the comments shared on the sidrops list since publication of v-13 -- from Claudio, Igor, Dai Zhibin, and Yangyang. 

Igor read the entire draft (pre-release v-14) and offered many editorial comments and also offered refinements to the Properties in Sec. 8. Thank you, Igor.

I have also carefully re-read and edited it for any remaining typos and grammatical errors, etc. 

Many thanks to all who have participated in the WGLC for very helpful suggestions, comments, and the insightful discussions.

Sriram

============================
-----Original Message-----
From: Lubashev, Igor <ilubashe@akamai.com> 
Sent: Tuesday, March 28, 2023 10:43 PM
To: Sriram, Kotikalapudi (Fed) <kotikalapudi.sriram@nist.gov>
Cc: sidrops@ietf.org; draft-ietf-sidrops-aspa-verification@ietf.org; draft-ietf-sidrops-aspa-profile@ietf.org
Subject: RE: [Sidrops] WGLC = draft-ietf-sidrops-aspa-verification - ENDS 03/22/2023 (Mar 22 2023)

Thanks, Sriram.  Yes, some additional clarification for the properties would be helpful.

I think it would be valuable to mention another "mitigation property".  When an AS generates ASPA, it makes it less likely that prefixes belonging to its customers will be hijacked, if the customers also generate ASPA.
A hijack attack that resists ASPA validation requires the hijacker to prepend its AS_PATH with a prefix containing the shortest possible sequence of ASNs identified as Providers in ASPA (transitively), starting from the hijacked ASN up to the first Provider ASN not in ASPA. When a provider generates ASPA, it forces attacker's AP_PATH to be one ASN longer, which reduces the likelihood of success of such hijack.

I think this could be a great business driver for ASPA adoption -- customers would be seeking out providers with an ASPA registration (and especially those whose providers also have ASPA registrations), since that would make their prefixes more resistant to hijacks. 

- Igor