8
Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Embed Size (px)

Citation preview

Page 1: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Ongoing work at the IETF on TCP and IP security

Fernando Gontproject carried out on behalf of

UK CPNI

HACK.LU 09 ConferenceOctober 28-30, 2009. Luxembourg

Page 2: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

TCP security “Security Assessment of the Transmission Control

Protocol (TCP)” Already adopted by the IETF (TCPM WG) http://tools.ietf.org/id/draft-ietf-tcpm-tcp-security-00.

txt Based on: http://www.cpni.gov.uk/Docs/tn-03-09-

security-assessment-TCP.pdf Join TCPM at: https://www.ietf.org/mailman/listinfo/

tcpm

Page 3: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

IP security “Security Assessment of the Internet Protocol

version 4 (IPv4)” Already adopted by the IETF (OPSEC WG) http://tools.ietf.org/id/draft-ietf-opsec-ip-security-01.txt Based on: http://www.cpni.gov.uk/Docs/

InternetProtocol.pdf Join OPSEC WG at: https://www.ietf.org/mailman/listinfo

/opsec

Page 4: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

NAT security “Security implications of Network Address

Translators (NATs)” Not yet adopted by the IETF http://tools.ietf.org/id/draft-ietf-opsec-ip-security-01.txt Based on:

http://www.cpni.gov.uk/Docs/InternetProtocol.pdf Join BEHAVE WG at:

https://www.ietf.org/mailman/listinfo/behave

Page 5: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Shameless plugin: IPv6 security Currently working on a security assessment of the

IPV6 suite Interested in finding people to discuss this stuff. Interested parties drop me an e-mail

([email protected])

Page 6: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Fernando [email protected]://www.gont.com.ar

Page 7: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg
Page 8: Ongoing work at the IETF on TCP and IP security Fernando Gont project carried out on behalf of UK CPNI HACK.LU 09 Conference October 28-30, 2009. Luxembourg

Current ongoing work at the IETF “Security Assessment of the Transmission Control

Protocol (TCP)” http://tools.ietf.org/id/draft-ietf-tcpm-tcp-security-00.tx

t Based on:

http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf

Join TCPM at: https://www.ietf.org/mailman/listinfo/tcpm

“Security Assessment of the Internet Protocol version 4 (IPv4)” http://tools.ietf.org/id/draft-ietf-opsec-ip-security-01.txt Based on:

http://www.cpni.gov.uk/Docs/InternetProtocol.pdf Join OPSEC WG at:

https://www.ietf.org/mailman/listinfo/opsec