site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Forum Rules ·Forum FAQ ·Bandwidth Limits/Congestion Management ·Copyright Infringement?
AuthorAll Replies


funchords
Hello
Premium,MVM
join:2001-03-11
Yarmouth Port, MA
kudos:5

reply to NSM998

Re: Comcast Announces Constant Guard Program

Sounds good, Nirmal & Jason. I'm doubtful but a Denver trial sounds like a way to find out for sure. I think the problem will be with user behavior, but maybe I'm jaded by my friend who turns off his AV everytime he tries to install software or play games because he believes it gets in the way.

My recommendation will be to make a panel out of people who were in a state to get the notice and learn:
1. Did they notice it and how long did it take?
2. Did they respond to it and when, how?
3. Did any applications fail to work?

It's important that you don't rely on Customer Support complaints. My expectation is that these folks won't call.

We have to compare these answers against the reality that these bots are not only harming the network but scamming folks. (I do know you guys intercept that junk from compromised hosts and assume you still will.)

This is a technicality in your FAQ above: How is DPI not involved in getting the proxy inserted in the flow? How are you getting HTTP traffic to pass through a proxy without DPI? (I did read Jason's 6A but I don't understand how DiffServ does anything with TCP port 80, that doesn't sound like DiffServ, that sounds like packet inspection, perhaps what some call Shallow Packet Inspection, but then you need DPI to do some forgery and redirection, right?.) If it turns out that it is technically DPI that makes this work, I think it's probably something okay since the alternative is a 100% walled-garden block and this clearly is a network management activity.
--
Robb Topolski -= funchords.com =- District of Columbia -- KJ7RL
Test your Broadband connection today! -- »measurementlab.net/


NSM998

join:2009-02-12
Philadelphia, PA

said by funchords:

Sounds good, Nirmal & Jason. I'm doubtful but a Denver trial sounds like a way to find out for sure. I think the problem will be with user behavior, but maybe I'm jaded by my friend who turns off his AV everytime he tries to install software or play games because he believes it gets in the way.

My recommendation will be to make a panel out of people who were in a state to get the notice and learn:
1. Did they notice it and how long did it take?
2. Did they respond to it and when, how?
3. Did any applications fail to work?

It's important that you don't rely on Customer Support complaints. My expectation is that these folks won't call.

We have to compare these answers against the reality that these bots are not only harming the network but scamming folks. (I do know you guys intercept that junk from compromised hosts and assume you still will.)

This is a technicality in your FAQ above: How is DPI not involved in getting the proxy inserted in the flow? How are you getting HTTP traffic to pass through a proxy without DPI? (I did read Jason's 6A but I don't understand how DiffServ does anything with TCP port 80, that doesn't sound like DiffServ, that sounds like packet inspection, perhaps what some call Shallow Packet Inspection, but then you need DPI to do some forgery and redirection, right?.) If it turns out that it is technically DPI that makes this work, I think it's probably something okay since the alternative is a 100% walled-garden block and this clearly is a network management activity.
We definitely did do a focus group study to understand user behavior and the feedback was positive. The system worked as expected when we tested it with the group as well as during our internal beta testing. The technical trial will provide further insight into how users behave and react to the notice. If we do get customer calls we are ready to help them as needed via our Customer Security Assurance team. So it will be a learning process.

On the DPI question....we use DSCP 9 to route the packets to the proxy that is it.....we use Squid which is not really a DPI application...its used strictly as a proxy (open source) and to support ICAP (RFC 3507). We explain the entire process in another I-D at »tools.ietf.org/html/draft-living···ation-00


funchords
Hello
Premium,MVM
join:2001-03-11
Yarmouth Port, MA
kudos:5

Thanks for the focus group info. (Just curious, can you share what percent of Denver you think will see this notice at some point during a day?)

said by NSM998:

On the DPI question....we use DSCP 9 to route the packets
I'm not sure we agree on what this means. At your convenience, can you please show me in an RFC where it talks about this handling? Again, I don't object that it is happening for this narrow security purpose, but I think DPI has to happen at some point to make it work.

said by NSM998:

to the proxy that is it.....we use Squid which is not really a DPI application...its used strictly as a proxy (open source) and to support ICAP (RFC 3507).
Yes, this part is understood. Plus, I read that draft.

Thanks!
--
Robb Topolski -= funchords.com =- District of Columbia -- KJ7RL
Test your Broadband connection today! -- »measurementlab.net/


jlivingood
Premium,VIP
join:2007-10-28
Philadelphia, PA
kudos:1

said by funchords:

I'm not sure we agree on what this means. At your convenience, can you please show me in an RFC where it talks about this handling? Again, I don't object that it is happening for this narrow security purpose, but I think DPI has to happen at some point to make it work.
Re DSCP (aka DiffServ), as you know DOCSIS and other IP networks can fairly easily use DSCP. In essence what we're doing is using DSCP to, for the brief period when we try to send the notification, route TCP/80 traffic to the squid proxy. Once the notification is sent, the DSCP is torn down.
--
JL
Comcast

Saturday, 02-Jun 08:45:14 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics