stoffi92 / rfc5575bis

0 stars 0 forks source link

IESG Benjamin Kaduk: Security stresses receiving systems #213

Closed stoffi92 closed 4 years ago

stoffi92 commented 4 years ago

Flow Specification BGP speakers (e.g. automated DDoS controllers) not properly programmed, algorithms that are not performing as expected, or simply rogue systems may announce unintended Flow Specifications, send updates at a high rate or generate a high number of Flow Specifications. This may stress the receiving systems, exceed their maximum capacity or may lead to unwanted Traffic Filtering Actions being applied to flows.

Is there any relevant guidance to give to receiving systems?

suehares commented 4 years ago

After you put in Barry's comment, the only addition is.
"Implementers of flow specification need to be aware of system-resource issues."

Again - ask Robert if this will be helpful.

stoffi92 commented 4 years ago

@raszuk can you please comment on this.

raszuk commented 4 years ago

"Implementers of flow specification need to be aware of system-resource issues."

The statement is correct however does not define what should be the protocol behaviour under system stress. Likewise BGP spec does not say a word what should implementation do when it run out of FIB space.

That is the vendor's secret sauce :)

So no harm to mention it - but just keep in mind that it may trigger a lot of questions and never ending discussions later.

On Thu, Apr 23, 2020 at 9:55 PM Christoph Loibl notifications@github.com wrote:

@raszuk https://github.com/raszuk can you please comment on this.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/stoffi92/rfc5575bis/issues/213#issuecomment-618629460, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAIH6EGVXUWOB4P65KN6L7DROCMK3ANCNFSM4MO2BZTA .

stoffi92 commented 4 years ago

//doc Not even the BGP spec says a word about what implementation should do when under stress or run out of FIB. This may not help to put it in FS