spacer datatracker.ietf.org
Sign In
  • Accounts
  • New Account
  • Working Groups
    • Applications
      • appsawg — Applications Area Working Group
      • core — Constrained RESTful Environments
      • eai — Email Address Internationalization
      • httpbis — Hypertext Transfer Protocol Bis
      • hybi — BiDirectional or Server-Initiated HTTP
      • imapmove — IMAP MOVE extension
      • iri — Internationalized Resource Identifiers
      • paws — Protocol to Access WS database
      • precis — Preparation and Comparison of Internationalized Strings
      • repute — Reputation Services
      • scim — System for Cross-domain Identity Management
      • spfbis — SPF Update
      • urnbis — Uniform Resource Names, Revised
      • websec — Web Security
      • weirds — Web Extensible Internet Registration Data Service
    • Internet
      • 6lowpan — IPv6 over Low power WPAN
      • 6man — IPv6 Maintenance
      • ancp — Access Node Control Protocol
      • csi — Cga & Send maIntenance
      • dhc — Dynamic Host Configuration
      • dmm — Distributed Mobility Management
      • dnsext — DNS Extensions
      • hip — Host Identity Protocol
      • homenet — Home Networking
      • intarea — Internet Area Working Group
      • l2tpext — Layer Two Tunneling Protocol Extensions
      • lisp — Locator/ID Separation Protocol
      • lwig — Light-Weight Implementation Guidance
      • mif — Multiple Interfaces
      • mip4 — Mobility for IPv4
      • multimob — Multicast Mobility
      • netext — Network-Based Mobility Extensions
      • ntp — Network Time Protocol
      • pcp — Port Control Protocol
      • pppext — Point-to-Point Protocol Extensions
      • savi — Source Address Validation Improvements
      • softwire — Softwires
      • sunset4 — Sunsetting IPv4
      • tictoc — Timing over IP Connection and Transfer of Clock
      • trill — Transparent Interconnection of Lots of Links
    • Ops & Mgmt
      • 6renum — IPv6 Site Renumbering
      • adslmib — ADSL MIB
      • bmwg — Benchmarking Methodology
      • dime — Diameter Maintenance and Extensions
      • dnsop — Domain Name System Operations
      • eman — Energy Management
      • grow — Global Routing Operations
      • ipfix — IP Flow Information Export
      • mboned — MBONE Deployment
      • netconf — Network Configuration
      • netmod — NETCONF Data Modeling Language
      • opsawg — Operations and Management Area Working Group
      • opsec — Operational Security Capabilities for IP Network Infrastructure
      • radext — RADIUS EXTensions
      • v6ops — IPv6 Operations
    • RAI
      • avtcore — Audio/Video Transport Core Maintenance
      • avtext — Audio/Video Transport Extensions
      • bfcpbis — Binary Floor Control Protocol Bis
      • bliss — Basic Level of Interoperability for SIP Services
      • clue — ControLling mUltiple streams for tElepresence
      • codec — Internet Wideband Audio Codec
      • cuss — Call Control UUI Service for SIP
      • dispatch — Dispatch
      • drinks — Data for Reachability of Inter/tra-NetworK SIP
      • ecrit — Emergency Context Resolution with Internet Technologies
      • geopriv — Geographic Location/Privacy
      • insipid — INtermediary-safe SIP session ID
      • mediactrl — Media Server Control
      • mmusic — Multiparty Multimedia Session Control
      • p2psip — Peer-to-Peer Session Initiation Protocol
      • payload — Audio/Video Transport Payloads
      • rtcweb — Real-Time Communication in WEB-browsers
      • salud — Sip ALerting for User Devices
      • simple — SIP for Instant Messaging and Presence Leveraging Extensions
      • sipclf — SIP Common Log Format
      • sipcore — Session Initiation Protocol Core
      • siprec — SIP Recording
      • soc — SIP Overload Control
      • straw — Sip Traversal Required for Applications to Work
      • vipr — Verification Involving PSTN Reachability
      • xmpp — Extensible Messaging and Presence Protocol
      • xrblock — Metric Blocks for use with RTCP's Extended Report Framework
    • Routing
      • bfd — Bidirectional Forwarding Detection
      • ccamp — Common Control and Measurement Plane
      • forces — Forwarding and Control Element Separation
      • idr — Inter-Domain Routing
      • isis — IS-IS for IP Internets
      • karp — Keying and Authentication for Routing Protocols
      • l2vpn — Layer 2 Virtual Private Networks
      • l3vpn — Layer 3 Virtual Private Networks
      • manet — Mobile Ad-hoc Networks
      • mpls — Multiprotocol Label Switching
      • nvo3 — Network Virtualization Overlays
      • ospf — Open Shortest Path First IGP
      • pce — Path Computation Element
      • pim — Protocol Independent Multicast
      • pwe3 — Pseudowire Emulation Edge to Edge
      • roll — Routing Over Low power and Lossy networks
      • rtgwg — Routing Area Working Group
      • sidr — Secure Inter-Domain Routing
    • Security
      • abfab — Application Bridging for Federated Access Beyond web
      • dane — DNS-based Authentication of Named Entities
      • emu — EAP Method Update
      • ipsecme — IP Security Maintenance and Extensions
      • jose — Javascript Object Signing and Encryption
      • kitten — Common Authentication Technology Next Generation
      • krb-wg — Kerberos
      • mile — Managed Incident Lightweight Exchange
      • nea — Network Endpoint Assessment
      • oauth — Web Authorization Protocol
      • pkix — Public-Key Infrastructure (X.509)
      • tls — Transport Layer Security
    • Transport
      • alto — Application-Layer Traffic Optimization
      • behave — Behavior Engineering for Hindrance Avoidance
      • cdni — Content Delivery Networks Interconnection
      • conex — Congestion Exposure
      • dccp — Datagram Congestion Control Protocol
      • fecframe — FEC Framework
      • ippm — IP Performance Metrics
      • ledbat — Low Extra Delay Background Transport
      • mptcp — Multipath TCP
      • nfsv4 — Network File System Version 4
      • ppsp — Peer to Peer Streaming Protocol
      • rmcat — RTP Media Congestion Avoidance Techniques
      • rmt — Reliable Multicast Transport
      • storm — STORage Maintenance
      • tcpm — TCP Maintenance and Minor Extensions
      • tsvwg — Transport Area Working Group
  • Active WGs
  • Chartering WGs
  • BoFs
  • Concluded WGs
  • Non-WG Lists
  • Drafts & RFCs
  • Document search:
  • Submit a draft
  • Sign in to track drafts
  • Meetings
  • Agenda
  • Materials
  • Past Proceedings
  • Upcoming
  • Other Documents
  • IPR Disclosures
  • Liaison Statements
  • IESG Agenda
  • Related Sites
  • Main IETF site
  • IETF tools
  • IAB
  • RFC Editor
  • IASA/IAOC/Trust
  • IANA
  • IRTF
Version 4.36, 2012-11-07
Report a bug

IODEF-extension to support structured cybersecurity information
draft-ietf-mile-sci-05

  • Document
  • IESG Evaluation Record
  • IESG Writeups
  • History
Active Internet-Draft (mile WG)
Document Stream: IETF
Last updated: 2012-10-15
Replaces: draft-takahashi-mile-sci
Intended RFC status: (None)
Other versions: plain text, pdf, html

IETF State: WG Document (mile)
Document shepherd:

IESG State: I-D Exists
Responsible AD: (None)
Send notices to: No addresses provided

View writeup
Email Authors | IPR Disclosures | Dependencies to this draft | Check nits | Search Mailing Lists
MILE Working Group                                          T. Takahashi
Internet-Draft                                                      NICT
Intended status: Standards Track                            K. Landfield
Expires: April 18, 2013                                           McAfee
                                                               T. Millar
                                                                  USCERT
                                                          Y. Kadobayashi
                                                                   NAIST
                                                            Oct 15, 2012

    IODEF-extension to support structured cybersecurity information
                       draft-ietf-mile-sci-05.txt

Abstract

   This document extends the Incident Object Description Exchange Format
   (IODEF) defined in RFC 5070 [RFC5070] to exchange enriched
   cybersecurity information among cybersecurity entities and facilitate
   their operations.  It provides the capability of embedding structured
   information, such as identifier- and XML-based information.

Status of this Memo

   This Internet-Draft is submitted in full conformance with the
   provisions of BCP 78 and BCP 79.

   Internet-Drafts are working documents of the Internet Engineering
   Task Force (IETF).  Note that other groups may also distribute
   working documents as Internet-Drafts.  The list of current Internet-
   Drafts is at datatracker.ietf.org/drafts/current/.

   Internet-Drafts are draft documents valid for a maximum of six months
   and may be updated, replaced, or obsoleted by other documents at any
   time.  It is inappropriate to use Internet-Drafts as reference
   material or to cite them other than as "work in progress."

   This Internet-Draft will expire on April 18, 2013.

Copyright Notice

   Copyright (c) 2012 IETF Trust and the persons identified as the
   document authors.  All rights reserved.

   This document is subject to BCP 78 and the IETF Trust's Legal
   Provisions Relating to IETF Documents
   (trustee.ietf.org/license-info) in effect on the date of
   publication of this document.  Please review these documents

Takahashi, et al.        Expires April 18, 2013                 [Page 1]
Internet-Draft                IODEF-ext-sci                     Oct 2012

   carefully, as they describe your rights and restrictions with respect
   to this document.  Code Components extracted from this document must
   include Simplified BSD License text as described in Section 4.e of
   the Trust Legal Provisions and are provided without warranty as
   described in the Simplified BSD License.

Table of Contents

   1.  Introduction . . . . . . . . . . . . . . . . . . . . . . . . .  3
   2.  Terminology  . . . . . . . . . . . . . . . . . . . . . . . . .  3
   3.  Applicability  . . . . . . . . . . . . . . . . . . . . . . . .  3
   4.  Extension Definition . . . . . . . . . . . . . . . . . . . . .  4
     4.1.  IANA Table for Structured Cybersecurity Information  . . .  4
     4.2.  Extended Data Types  . . . . . . . . . . . . . . . . . . .  5
       4.2.1.  XMLDATA  . . . . . . . . . . . . . . . . . . . . . . .  5
     4.3.  Extended Classes . . . . . . . . . . . . . . . . . . . . .  5
       4.3.1.  AttackPattern  . . . . . . . . . . . . . . . . . . . .  6
       4.3.2.  Platform . . . . . . . . . . . . . . . . . . . . . . .  8
       4.3.3.  Vulnerability  . . . . . . . . . . . . . . . . . . . .  9
       4.3.4.  Scoring  . . . . . . . . . . . . . . . . . . . . . . . 11
       4.3.5.  Weakness . . . . . . . . . . . . . . . . . . . . . . . 12
       4.3.6.  EventReport  . . . . . . . . . . . . . . . . . . . . . 13
       4.3.7.  Verifcation  . . . . . . . . . . . . . . . . . . . . . 15
       4.3.8.  Remediation  . . . . . . . . . . . . . . . . . . . . . 16
   5.  Mandatory to Implement features  . . . . . . . . . . . . . . . 17
   6.  Security Considerations  . . . . . . . . . . . . . . . . . . . 18
     6.1.  Transport-Specific Concerns  . . . . . . . . . . . . . . . 18
   7.  IANA Considerations  . . . . . . . . . . . . . . . . . . . . . 18
   8.  Acknowledgment . . . . . . . . . . . . . . . . . . . . . . . . 20
   9.  Appendix I: XML Schema Definition for Extension  . . . . . . . 20
   10. Appendix II: Candidate Specifications for the IANA Table . . . 25
   11. Appendix III: An XML Example . . . . . . . . . . . . . . . . . 28
   12. References . . . . . . . . . . . . . . . . . . . . . . . . . . 30
     12.1. Normative References . . . . . . . . . . . . . . . . . . . 30
     12.2. Informative References . . . . . . . . . . . . . . . . . . 31
   Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . . 33

Takahashi, et al.        Expires April 18, 2013                 [Page 2]
[include full document text]
gipoco.com is neither affiliated with the authors of this page nor responsible for its contents. This is a safe-cache copy of the original web site.