Re: [Spud] updated draft PLUS charter, rev. 1 June

Christian Huitema <huitema@microsoft.com> Fri, 10 June 2016 20:12 UTC

Return-Path: <huitema@microsoft.com>
X-Original-To: spud@ietfa.amsl.com
Delivered-To: spud@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA28412D0FB for <spud@ietfa.amsl.com>; Fri, 10 Jun 2016 13:12:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.003
X-Spam-Level:
X-Spam-Status: No, score=-2.003 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ao1mVesGgKNi for <spud@ietfa.amsl.com>; Fri, 10 Jun 2016 13:12:44 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0123.outbound.protection.outlook.com [65.55.169.123]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CCF412D786 for <spud@ietf.org>; Fri, 10 Jun 2016 13:12:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=rLIIbySK6305F8U5t+llVnoFFXzxHq9wq2Uz4c8lE8M=; b=OIoBSg+YDI3k+XZ/dL71+aaHRIhuigdO6EKKMHjEFCcxOwooNhVFEBg3y4P/HCexWt3WXS//Glk20ofseyHZL1XnaZd4uzFYb/MBJHDyogsBkSTxY7fuWa9lAP4vDosfjKu4GDpcGl0fD21xWBa31Q50tnrU0Pi2bEjVIAcQCzM=
Received: from DM2PR0301MB0655.namprd03.prod.outlook.com (10.160.96.17) by DM2PR0301MB0654.namprd03.prod.outlook.com (10.160.96.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.517.8; Fri, 10 Jun 2016 20:12:42 +0000
Received: from DM2PR0301MB0655.namprd03.prod.outlook.com ([10.160.96.17]) by DM2PR0301MB0655.namprd03.prod.outlook.com ([10.160.96.17]) with mapi id 15.01.0517.005; Fri, 10 Jun 2016 20:12:42 +0000
From: Christian Huitema <huitema@microsoft.com>
To: Tom Herbert <tom@herbertland.com>, Brian Trammell <ietf@trammell.ch>
Thread-Topic: [Spud] updated draft PLUS charter, rev. 1 June
Thread-Index: AQHRu/KkknslUV6vnUS4tzs14whv9J/eT28AgAABG4CAAB43AIAABfgAgAADLQCAABjYgIAABqUAgAACJQCAAAEtgIAAAqWAgAAEkgCAAGJBAIAAZ68AgAHaSoCAABM7AIABf52AgAAH0gCAAAqNAIAAQ7cA
Date: Fri, 10 Jun 2016 20:12:41 +0000
Message-ID: <DM2PR0301MB06554C7A8277C06E0119AA7EA8500@DM2PR0301MB0655.namprd03.prod.outlook.com>
References: <85E24D9D-F666-49C3-A022-2F207227A153@trammell.ch> <CAD62q9UiLi1ffGPm=xEXOSH=sqZPv7hYiNBTGvAX52a9dhV8yg@mail.gmail.com> <CAD62q9U7XL8hDqY1VdzuvUvoz0Ec5DDLAS6=kaLxRExu7FY0Kg@mail.gmail.com> <86027402-2F05-4E3B-B9CD-26517A4F007C@tik.ee.ethz.ch> <A4C63A75-9D7E-430E-B986-9981FB929D46@gmail.com> <CA+9kkMBhJ2oCJ1avnGUY4NYTX0VWA_g=YoJSiLcy6u9hJnH-eA@mail.gmail.com> <57573DCF.1030402@isi.edu> <F6BE4EE1-D320-421E-9D86-2F30B2A88792@tik.ee.ethz.ch> <CALx6S35Z7iEp2F7+1PHzAe0qu9st_CNXB9GCzF278HehFiv0Qg@mail.gmail.com> <0f5628e2-a142-8d83-b427-d6b07183cb9e@isi.edu> <CALx6S35KXOioEK60p-m5tGE_H9MWbB=YhJ_sOcW0KP2vR80vvw@mail.gmail.com> <57574C38.6070402@isi.edu> <F44FFD3B-CE7E-45E8-9F04-233C56CA95A0@trammell.ch> <890FE014-D3F8-4D64-8BF8-95B3E4773075@trammell.ch> <CALx6S34jbmaV7vAxr1+-p2HW9i2oKv7Bb138MzsaP71zVh=PQw@mail.gmail.com> <76A9F36B-9C21-4268-8267-16D0D9A78834@trammell.ch> <CALx6S37uONysFMNJgUs430eFEUuNTMuhcYKtCPBPMs5W6godVQ@mail.gmail.com> <780953BA-CE7B-4B17-AB9A-27324246FB86@trammell.ch> <CALx6S374mn6pwrSMmEdE5p60zPOu+77+M6HkA8w43GBO1xLvFg@mail.gmail.com>
In-Reply-To: <CALx6S374mn6pwrSMmEdE5p60zPOu+77+M6HkA8w43GBO1xLvFg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=huitema@microsoft.com;
x-originating-ip: [2001:4898:80e8:e::59a]
x-ms-office365-filtering-correlation-id: 9f6fb4e2-6b87-4d84-fd15-08d3916b9437
x-microsoft-exchange-diagnostics: 1; DM2PR0301MB0654; 6:vePCuSjqsEq6Jhb9xo3Yb7CG61MFLt4mioYqAKSOnNMpuukV0hgx0ikvDuhL9HevPJAmD+AWRtv4MSDAYvK+n7llsmul/1BfkNRvwoLJj4XzopH5AO5Maf6owVL3uizNMLk6YPHoH8djA3oOZ1/qpbTnnQr0GEukfheg90zAaGrCJg87YRIYb2gQDeSiLnUzOprGZFnn87IUozZxoymoZFgSzIVMpItY0j54Nkx6MghWsd9ydztW/aAM5OBx14Xxhw3bEvCDEqaagAbUif6Ym+dUeYmBuiPGrGoW8I1Tc5/Jaqcxo21I8Bjg6fRXtya3; 5:bbsdvNwokioAA3Nc64t1ws9JOJGWvfbT4ojUiI+EOB/Flk8kCgrgX4nJ0unHDdeE6RqW51nCGfINuaKHvon+dU7fQ1Yf0zIRrUFPLDSvoXjoeSFTkEyIq6mmm2x5DV8gCMgo4gP80D2VF1yFP0EIhg==; 24:c8tcnvYfiyDK2HPTej/x0UKQIYm2duAtAlUD1CeYRieZNN4gJ5ATTmKszuaey+8elvdCiySsW305qCSOfeoYioPdUplJkNVHRBAX3S51Leo=; 7:2fNW5WlTdIaZt6OC3M8nJlaS+fIvclWQ9by8di7Kolbe/1dTMkDTnELY3e3jrecRkRfuV1gjf2mEgOTpxTdnWQSsy4BMCR9cCjAEhkfzOsFI4SYa0C8Yc6gvrvQXkkYi7ks7d2lf8yMYCsQMUeXCunUoLtUnn+0lUGrrR/2fwR4wDwsIMSFYOTpTlzXGwqdb3g6buTHecQUJc85hXNeE/SMq1t6NoWi2lD6kZJzFm9PqWUnV0QAlIKh0FKuP7KIT
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DM2PR0301MB0654;
x-microsoft-antispam-prvs: <DM2PR0301MB06542BBFE7005F7E3CDB77D0A8500@DM2PR0301MB0654.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6055026)(61426038)(61427038); SRVR:DM2PR0301MB0654; BCL:0; PCL:0; RULEID:; SRVR:DM2PR0301MB0654;
x-forefront-prvs: 096943F07A
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(7916002)(377454003)(189002)(24454002)(199003)(76176999)(122556002)(54356999)(50986999)(2900100001)(77096005)(2950100001)(74316001)(86612001)(93886004)(106356001)(106116001)(105586002)(97736004)(5004730100002)(5002640100001)(6116002)(5008740100001)(9686002)(102836003)(5001770100001)(586003)(10290500002)(99286002)(189998001)(86362001)(92566002)(4326007)(2906002)(5003600100002)(68736007)(15650500001)(76576001)(3280700002)(11100500001)(3660700001)(10400500002)(5005710100001)(101416001)(8676002)(87936001)(81166006)(10090500001)(8936002)(81156014)(8990500004)(33656002)(3826002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0301MB0654; H:DM2PR0301MB0655.namprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; CAT:NONE; LANG:en; CAT:NONE;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 10 Jun 2016 20:12:41.6187 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0301MB0654
Archived-At: <https://mailarchive.ietf.org/arch/msg/spud/mHnRGEdhl0AFvoQyjX3Ml1-vJgY>
Cc: spud <spud@ietf.org>
Subject: Re: [Spud] updated draft PLUS charter, rev. 1 June
X-BeenThere: spud@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Session Protocol Underneath Datagrams <spud.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spud>, <mailto:spud-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spud/>
List-Post: <mailto:spud@ietf.org>
List-Help: <mailto:spud-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spud>, <mailto:spud-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Jun 2016 20:12:46 -0000

On Friday, June 10, 2016 9:04 AM, Tom Herbert wrote:
> ...
> Plus introduces new issues. All prior uses of UDP on the Internet have been end
> to end communications, application to application. PLUS is introducing the
> notion that UDP is used for application to network and network to application
> communications also. For end to end communications we can apply strong
> security (e.g. DTLS) so that spoofed or reflected UDP packets are not accepted.

I think Tom has a good point here. PLUS does introduce new communication patterns, passing information to intermediate routers and expecting routers to act on the information. These communication patterns can very well introduce new attack vectors. We actually discussed a few of those on the list some time back. For example, an attacker could inject a packet that mimics the closure of a flow, and cause intermediate firewalls to close the holes open for that flow.

I suggest that we recognize the link between new patterns and new attacks in the charter, and have an explicit goal to investigate these attacks and their mitigations. 

-- Christian Huitema