RFC 3837 - Security Threats and Risks for Open Pluggable Edg(2)

时间:2006-10-31 来源: 作者: 点击:
action. 3.4.InconsistentPrivacyPolicy TheOPESentitiesmayhaveprivacypoliciesthatarenotconsistent withthedataconsumerapplicationorcontentproviderapplication. Privacyrelatedproblemsmaybefurthercomplicat
  
   action.

3.4.  Inconsistent Privacy Policy

   The OPES entities may have privacy policies that are not consistent
   with the data consumer application or content provider application.

   Privacy related problems may be further complicated if OPES entities,
   content providers, and end users belong to different jurisdictions
   with different requirements and different levels of legal protection.
   As a result, the end user may not be aware that he or she does not
   have the expected legal protection.  The content provider may be
   exposed to legal risks due to a  failure to comply with regulations
   of which he is not even aware.

3.5.  Exposure of Privacy Preferences

   The OPES system may inadvertently or maliciously expose end user
   privacy settings and requirements.

3.6.  Exposure of Security Settings

   There are risks that the OPES system may expose end user security
   settings when handling the request and responses.  The user data must
   be handled as sensitive system information and protected against
   accidental and deliberate disclosure.

3.7.  Improper Enforcement of Privacy and Security Policy

   OPES entities are part of the content distribution system and as such
   take on certain obligations to support security and privacy policies
   mandated by the content producer and/or end user.  However there is a
   danger that these policies are not properly implemented and enforced.
   The data consumer application may not be aware that its protections
   are no longer in effect.

   There is also the possibility of security and privacy leaks due to
   the accidental misconfiguration or, due to misunderstanding what
   rules are in effect for a particular user or request.

   Privacy and security related parts of the systems can be targeted by
   malicious attacks and the ability to withstand such attacks is of
   paramount importance.

3.8.  DoS Attacks

   DoS attacks can be of various types.  One type of DoS attack takes
   effect by overloading the client.  For example, an intruder can
   direct an OPES processor to issue numerous responses to a client.
   There is also additional DoS risk from a rule misconfiguration that
   would have the OPES processor ignore a data consumer application.

4.  Security Considerations

   This document discusses multiple security and privacy issues related
   to the OPES services.

5.  References

5.1.  Normative References

   [1]  Barbir, A., Penno, R., Chen, R., Hofmann, M., and H. Orman, "An
        Architecture for Open Pluggable Edge Services (OPES)", RFC 3835,
        August 2004.

   [2]  Barbir, A., Burger, E., Chen, R., McHenry, S., Orman, H., and R.
        Penno, "OPES Use Cases and Deployment Scenarios", RFC 3752,
        April 2004.

   [3] Barbir, A., Batuner, O., Beck, A., Chan, T., and H. Orman,
        "Policy, Authorization, and Enforcement Requirements of Open
        Pluggable Edge Services (OPES)", RFC 3838, August 2004.

5.2.  Informative References

   [4]  Floyd, S. and L. Daigle, "IAB Architectural and Policy
        Considerations for Open Pluggable Edge Services", RFC 3238,
        January 2002.

6.  Acknowledgements

   Many thanks to T. Chan (Nokia) and A. Beck (Lucent).

7.  Authors’ Addresses

   Abbie Barbir
   Nortel Networks
   3500 Carling Avenue
   Nepean, Ontario  K2H 8E9
   Canada

   Phone: +1 613 763 5229
   EMail: abbieb@nortelnetworks.com

   Oskar Batuner
   Independent consultant

   EMail: batuner@attbi.com

   Bindignavile Srinivas
   Nokia
   5 Wayside Road
   Burlington, MA  01803
   USA

   EMail: bindignavile.srinivas@nokia.com

   Markus Hofmann
   Bell Labs/Lucent Technologies
   Room 4F-513
   101 Crawfords Corner Road
   Holmdel, NJ  07733
   US

   Phone: +1 732 332 5983
   EMail: hofmann@bell-labs.com

   Hilarie Orman
   Purple Streak Development

   EMail: ho@alum.mit.edu

8.  Full Copyright Statement

   Copyright (C) The Internet Society (2004).  This document is subject
   to the rights, licenses and restrictions contained in BCP 78, and
   except as set forth therein, the authors retain all their rights.

   This document and the information contained herein are provided on an
   "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS
   OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND THE INTERNET
   ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED,
   INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
   INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED
   WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

Intellectual Property

   The IETF takes no position regarding the validity or scope of any
   Intellectual Property Rights or other rights that might be claimed to
   pertain to the implementation or use of the technology described in
   this document or the extent to which any license under such rights
   might or might not be available; nor does it represent that it has
   made any independent effort to identify any such rights.  Information
   on the procedures with respect to rights in RFC documents can be
   found in BCP 78 and BCP 79.

   Copies of IPR disclosures made to the IETF Secretariat and any
   assurances of licenses to be made available, or the result of an
   attempt made to obtain a general license or permission for the use of
   such proprietary rights by implementers or users of this
   specification can be obtained from the IETF on-line IPR repository at
   http://www.ietf.org/ipr.

   The IETF invites any interested party to bring to its attention any
   copyrights, patents or patent applications, or other proprietary
   rights that may cover technology that may be required to implement
   this standard.  Please address the information to the IETF at ietf-
   ipr@ietf.org.

Acknowledgement

   Funding for the RFC Editor function is currently provided by the
   Internet Society.
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容