Re: [I2nsf] Definitions in draft-merged-i2nsf-problem-statement-use-cases-00
DIEGO LOPEZ GARCIA <> Tue, 15 December 2015 21:50 UTC
To: Robert Moskowitz <>
Date: Tue, 15 Dec 2015 21:48:57 +0000
Cc: "" <>
Subject: Re: [I2nsf] Definitions in draft-merged-i2nsf-problem-statement-use-cases-00
Hi Bob, I would support your proposal without the quotes and a "can" before what the NSF can help to achieve. Thus: A function that detects unwanted activity and blocks/mitigates the effect of such unwanted activity in order to support availability of a network. In addition, the NSF can help in supporting communication stream integrity and confidentiality I don't think detecting unwanted activity is too self-assured: unwanted activity is what the user and/or provider of the NSF has defined they do not want. Whatever the activity that matches with this definition is unwanted and the NSF will do whatever they can to stop it. Be goode, On 11 Dec 2015, at 13:04 , Robert Moskowitz <<>> wrote: I have been working with Sue and Linda on reviewing and cleaning up this ID. I looked at; Network Security Function (NSF): A function which ensures integrity, confidentiality and availability of network communications; detects unwanted activity, blocks or mitigates the effect of such unwanted activity on the network. And I took exception with at least 'ensures'. This is too strong of a statement. Nothing we do with this technology will 'ensure' CIA. First what is 'CIA': Confidentiality by restricting access to the internal assets. Integrity by, (well gee, what IS Integrity)? Integrity by enabling users to trust using their assets. Availablity by blocking attacks that make assets unusable. So first, do we agree what CIA means and that it is important? If so, we might get something like: A function that detects unwanted activity and blocks/mitigates the effect of such unwanted activity in order to support availability of a network. In addition, the NSF helps support communication stream "integrity and confidentiality". Even this is too self-assured. An NSF detects unwanted activity? Really? It detects what we have so far have classified as unwanted activity. I know that IPS NSF devices are marketed to 'learn' and adapt, but without sophisticated AI, even here there are limits. Perhaps I am too pedantic, but this document includes 'user expectations', and I don't want an expectation of '6 sigmas of detection'. My sixpence worth. _______________________________________________ I2nsf mailing list<> -- "Esta vez no fallaremos, Doctor Infierno" Dr Diego R. Lopez Telefonica I+D e-mail: Tel: +34 913 129 041 Mobile: +34 682 051 091
