Operational Security Capabilities for IP Network Infrastructure

Slides:



Advertisements
Similar presentations
IETF Calsify.
Advertisements

1 ISMS WG 79th IETF Beijing November 10, 2010 Goal:Creating a security model for SNMPv3 that will meet the security and operational needs of network administrators.
PPSP WG IETF-80, Prague, March 28, 2011 Chairs: Yunfei Zhang Cullen Jennings Jabber:
IETF 64 P2PSIP AdHoc Meeting Remembrance Day November 11, 2005 Vancouver, BC, Canada David A. Bryan.
L2VPN WG “NVO3” Meeting IETF 82 Taipei, Taiwan. Agenda Administrivia Framing Today’s Discussions (5 minutes) Cloud Networking: Framework and VPN Applicability.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
PPSP Working Group IETF-89 London, UK 16:10-18:40, Tuesday, Webex: participation.html.
CCAMP Working Group Online Agenda and Slides at: Tools start page:
DRINKS Interim („77.5“) Reston, VA Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF.
IETF 90: NetExt WG Meeting. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet- Draft.
Multiple Interfaces (MIF) WG IETF 78, Maastricht, Netherlands Margaret Wasserman Hui Deng
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
DISPATCH WG: ad hoc meeting on DREGS IETF-76 Mary Barnes (Dispatch WG co-chair) Eric Burger (ad hoc chair) 12 November DREGS ad hoc (DISPATCH) IETF.
SIPCLF Working Group Spencer Dawkins Theo Zourzouvillys IETF 76 – November 2009 Hiroshima, Japan.
IETF-63 OPSEC WG OPSEC WG _______ Operational Security Capabilities for IP Network Infrastructure IETF #65 - Dallas.
IETF #82 DRINKS WG Meeting Taipei, Taiwan Fri, Nov 18 th
HIP Working Group IETF 62 Gonzalo Camarillo David Ward.
1 NOTE WELL Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Multi6 Working Group IETF-61, Washington D.C November 8-12, 2004.
GROW IETF 78 Maastricht, Netherlands. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft.
IETF 86 PIM wg meeting. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC.
IETF 79 - Beijing, China1 Martini Working Group IETF 79 Beijing Chairs: Bernard Spencer
Extensible Messaging and Presence Protocol (XMPP) WG Interim Meeting, Monday, January 7,
Peer to Peer Streaming Protocol (PPSP) BOF Gonzalo Camarillo Ericsson Yunfei Zhang China Mobile IETF76, Hiroshima, Japan 13:00~15:00 THURSDAY, Nov 12,
IPPM WG IETF 79. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and.
Tictoc working group Thursday, 28 July – 1720 EDT (1920 – 2120 UTC) Karen O’Donoghue and Yaakov Stein, co-chairs.
CCAMP Working Group Online Agenda and Slides at: Data tracker:
Web Authorization Protocol (oauth) Hannes Tschofenig.
IETF #86 - NETCONF WG session 1 NETCONF WG IETF 86 - Orlando, FL, USA MONDAY, March 11, Bert Wijnen Mehmet Ersue.
IETF DRINKS Interim Meeting (#82.5) Virtual Interim Meeting Wed, Feb 1 st p-6p UTC/9a-1p Eastern.
Emergency Context Resolution with Internet Technologies BOF (ecrit) Jon Peterson, Hannes Tschofenig BOF Chairs.
Diameter Maintenance and Extensions (dime) IETF 68, March 2007, Prague David Frascone, Hannes Tschofenig.
Wed 24 Mar 2010SIDR IETF 77 Anaheim, CA1 SIDR Working Group IETF 77 Anaheim, CA Wednesday, Mar 24, 2010.
Routing Area WG (rtgwg) IETF 84 – Vancouver Chairs: Alia Atlas Alvaro Retana
ECRIT IETF 70 December 2007 Vancouver Hannes Tschofenig Marc Linsner Roger Marshall.
Authentication and Authorization for Constrained Environment (ACE) WG Chairs: Kepeng Li, Hannes
IETF 89, LONDON, UK LISP Working Group. 2 Agenda and slides:  lisp.html Audio Stream 
DMM WG IETF 84 DMM WG Agenda & Status Tuesday, July 31 st, 2012 Jouni Korhonen, Julien Laganier.
1 Transport Area Open Meeting Lars Eggert & Magnus Westerlund IETF-69 Chicago, IL, USA
LMAP WG IETF 92, Dallas, TX Dan Romascanu Jason Weil.
March 2008IETF KMART BoF1 KMART BOF Key Management for Routing Co-Chairs: Acee Lindem Donald Eastlake 3rd
Transport Layer Security (TLS) IETF-84 Chairs: Eric Rescorla Joe Salowey.
Interface to the Routing System (IRS) BOF IETF 85, Atlanta November 2012.
IPR WG IETF 62 Minneapolis. IPR WG: Administrivia Blue sheets Scribes Use the microphones Note Well.
IETF #81 - NETCONF WG session 1 NETCONF WG IETF 81, Quebec City, Canada MONDAY, July 25, Bert Wijnen Mehmet Ersue.
3 August th IETF - San Diego, CA, USA1 SPEECHSC Eric Burger Dave Oran
Transport Layer Security (TLS) IETF 73 Thursday, November Chairs: Eric Rescorla Joe Salowey.
IETF #73 - NETMOD WG session1 NETMOD WG IETF 73, Minneapolis, MN, USA November 20, David Harrington David Partain.
Transport Layer Security (TLS) IETF-78 Chairs Joe Salowey Eric Rescorla
HIP WG Gonzalo Camarillo David Ward IETF 80, Prague, Czech Republic THURSDAY, March 31, 2011, Barcelona/Berlin.
OPSREA Open Meeting Area Directors: Dan Romascanu and Ron Bonica Monday, March 28, 2011 Morning Session, 10:30 – 11:30, Room Barcelona/Berlin Discussion.
Agenda Behcet Sarikaya Dirk von Hugo November 2012 FMC BOF IETF
MODERN BoF Managing, Ordering, Distributing, Exposing, and Registering telephone Numbers IETF 92.
IETF #82 - NETCONF WG session 1 NETCONF WG IETF 82, Taipei, Taiwan TUESDAY, November 15, Afternoon Session III Bert Wijnen Mehmet Ersue.
Emergency Context Resolution with Internet Technologies (ecrit) Hannes Tschofenig, Marc Linser Chairs.
Opsawg chairs Scott Bradner Chris Liljenstolpe. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an.
Agenda Stig Venaas Behcet Sarikaya November 2011 Multimob WG IETF
OPSAWG chairs: Scott Bradner Christopher Liljenstolpe.
STIR Secure Telephone Identity Revisited
Agenda Stig Venaas Behcet Sarikaya November 2010
Gunter Van de Velde Kiran Kumar Chitimaneni Warren Kumari
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Kathleen Moriarty, Trusted Execution Environment Provisioning (TEEP) BoF IETF-100 November 2017 Chairs: Nancy Cam-Winget,
Multiple Interfaces (MIF) WG
SIPREC WG, Interim virtual meeting , GMT
TEAS CCAMP MPLS PCE Working Groups
SIPBRANDY Chair Slides
Multiple Interfaces (MIF) WG
Scott Bradner & Martin Thomson
NETCONF WG IETF 80, Prague, Czech Republic March 31,
Presentation transcript:

Operational Security Capabilities for IP Network Infrastructure OPSEC WG _______ Operational Security Capabilities for IP Network Infrastructure IETF #61 IETF-61 OPSEC WG

Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made within the context of an IETF activity is considered an "IETF Contribution". Such statements include oral statements in IETF sessions, as well as written and electronic communications made at any time or place, which are addressed to: the IETF plenary session, any IETF working group or portion thereof, the IESG, or any member thereof on behalf of the IESG, the IAB or any member thereof on behalf of the IAB, any IETF mailing list, including the IETF list itself, any working group or design team list, or any other list functioning under IETF auspices, the RFC Editor or the Internet-Drafts function All IETF Contributions are subject to the rules of RFC 3667 and RFC 3668. Statements made outside of an IETF session, mailing list or other function, that are clearly not intended to be input to an IETF activity, group or function, are not IETF Contributions in the context of this notice. Please consult RFC 3667 for details. IETF-61 OPSEC WG

Front Administrativia Note scribe. Jabber scribe (opsec) ietfxmpp.org When speaking: Please identify yourself (for the scribes) Don’t mumble IETF-61 OPSEC WG

Agenda 1. Agenda bashing. 2. The Charter. [ Pat/Ross] <http://www.ietf.org/html.charters/opsec-charter.html>. 3. The Framework Doc. <draft-jones-opsec-framework-01.txt> * Overview (George) * Threats (Merike) 4. The Standards Survey Doc. <draft-lonvick-sec-efforts-01.txt> 5. The Survey of Service Provider Security Practices Doc. [ Merike ] 6. Go home. IETF-61 OPSEC WG

Charter: Scope The working group will list capabilities appropriate for devices used in: * Internet Service Provider (ISP) Networks * Enterprise Networks The following areas are excluded: * Wireless devices * Small-Office-Home-Office (SOHO) devices * Security devices (firewalls, Intrusion Detection Systems, Authentication Servers) * End Hosts The plan is to have multiple small documents IETF-61 OPSEC WG

Charter: Outputs Framework Document Current Practices Document The plan, scope, etc Current Practices Document * threats addressed, * current practices for addressing the threat, * protocols, tools and technologies extant at the time of writing Individual Capability Documents The detail for the various categories Profile Documents IETF-61 OPSEC WG

Profiles/Capabilities in Charter ISP Operational Security Capabilities Profile Enterprise Operational Security Capabilities Profile Capabilities: Packet Filtering Event Logging In-Band management Out-of-Band management Configuration and Management Interface Authentication, Authorization and Accounting (AAA) Documentation and Assurance Miscellaneous IETF-61 OPSEC WG

Charter-related issues There are a lot of documents The document tradeoff: One really big on versus many tiny ones. We need lots of editors  IETF-61 OPSEC WG

Framework Doc <draft-jones-opsec-framework-01.txt> Specified in charter IETF-61 OPSEC WG

OPSEC Working Group Framework Document George Jones gmjones@mitre.org November 9, 2004 IETF-61 OPSEC WG

Framework Overview + Framework defines docs, work, scope, threats, attacks, etc. + Standards Survey surveys related work (Chris) + Operator Practices Survey lists current practices (Merike) + Capability docs list capabilities to support current and future practices. IETF-61 OPSEC WG

- Framework Changes in -01: + Attacks/Threat Model (Merike) + 1,$s/Requirements/Capabilities/g - Framework Changes for -02 ? + Need to correlate charter and framework document lists. + Drop list of documents from framework ? + Need to clarify intended status of documents. + Reduce # of documents ? IETF-61 OPSEC WG

Standards Efforts <draft-lonvick-sec-efforts-01.txt> Not currently a workgroup document Should it be? IETF-61 OPSEC WG

Survey of Current Practices <no-draft-yet> Specified in charter IETF-61 OPSEC WG

Table of Contents IETF-61 OPSEC WG 1. Introduction 2. Problem Statement 3. Device Access Security 3.1 Threat Description 3.2 Best Current Practice 3.2.1 Logical access 3.2.2 Console Access 3.2.3 HTTP 3.2.4 SNMP 4. Authentication / Authorization 4.1 Threat Description 4.2 Best Current Practice 4.2.1 Device Access 4.2.2 Routing 4.2.3 MAC Address 5. Filtering 5.1 Threat Description 5.2 Best Current Practice 5.2.1 General Inbound Traffic Filters 5.2.2 General Outbound Traffic Filters 5.2.3 Device Access Filters 5.2.4 Route Filters 5.2.5 MAC Address Filters 5.2.6 DoS Mitigation Filtering 5.2.7 SinkHole / Blackhole 5.2.8 uRPF 6. Logging (accounting) 6.1 Threat Description 6.2 Best Current Practice 6.2.1 What traffic is logged 6.2.2 What fields are logged 6.2.3 How long are logs kept 6.2.4 Local buffer vs syslog (for backup info) 6.2.5 Authentication from peer to peer of log files? 6.2.6 Integrity check of log files? 6.2.7 NTP source considerations 7. Device Integrity 7.1 Threat Description 7.2 Best Current Practice 7.2.1 Device Image Upgrade 7.2.2 Device Configuration 7.2.3 Management/Logging Information 8. Specific Protocol/Service Concerns 8.1 Threat Description 8.2 Best Current Practice 8.2.1 ICMP 8.2.2 Generally Unused Services 9. Policy/Procedural Considerations 9.1 Threat Description 9.2 Best Current Practice 9.2.1 Equipment Software Update 9.2.2 Equipment Configuration Change IETF-61 OPSEC WG

Discussion/Administratia Time for Discussion Maillist: General Discussion: opsec@ops.ietf.org To Subscribe: opsec-request@ops.ietf.org In Body: subscribe Archive: http://ops.ietf.org/lists/opsec/ IETF-61 OPSEC WG