Re: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt

Andrew S2 <andrew.s2@ncsc.gov.uk> Tue, 20 September 2022 15:45 UTC

Return-Path: <andrew.s2@ncsc.gov.uk>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3CC78C14F728 for <opsec@ietfa.amsl.com>; Tue, 20 Sep 2022 08:45:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.913
X-Spam-Level:
X-Spam-Status: No, score=-7.913 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.233, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ncsc.gov.uk
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4Ax-vaEuiE2x for <opsec@ietfa.amsl.com>; Tue, 20 Sep 2022 08:45:44 -0700 (PDT)
Received: from GBR01-LO2-obe.outbound.protection.outlook.com (mail-lo2gbr01on2091.outbound.protection.outlook.com [40.107.10.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ACC35C152562 for <opsec@ietf.org>; Tue, 20 Sep 2022 08:45:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LtLdwQYruQjnonTmYd7/CKIhiX6f7zXP0Npu04etAYNKoKS0eofT4OAohM5xgmwH+00suKA9GOCX00uz6M0fTrq02rL7Nrnom9EnCfVp05/ncYR/61XAiou7PzU16jkAqyQdEGzqYHaP2C1M1zWk3FHm5vFx5hAVdaKwlgFOZ3mxM1+GzKa2XQFF5JTePZgEosfP+NzMgVwwkDfb5q9uo5qnd6E93p2WJJjqMsCKT+lM91Dg4wPWcYyK0oK42KP/sK/+dmgfoazOtCDrbmFuu6c4VJYj6de02HqO7dYuV4p8ksb6Ki+1Zas7T4BkFvgYvnPmT5iKv+KcOnOZOPzlQA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=HPkJqsd6ytCLGmdqQUXJ7iszwNdwLTBVOwmJJ6jeq4A=; b=j8Ff0Od7HKjwzSTxbnK6eJvDuvKF0Lk82J+45b1KvSRoNVpE0vGwgJG+4bSxldjtW3cZe59E4UT7EWISFyk9oONayYCdaUbLktw/2r2/5LoP/ZiiRqKtBvV0s/fh4CbGYQufvyDzTjfWHT3QvWMTF2q4hofgkMSdll0XKMgEwUJTT0LVECNh2ViMVFPtNMvjSzDvRJMaQaqL9nUMH24npxfGemu/SzbsgIiNUjpJSYhoxPuo/f4qKguVmpsT2gFdUvuQdUHK6w0jEunRcT+kn4noLaO7Bo2tXKMl2UFPfCGjFYBEuGyrcivliRf6PjHt9xD03MbAAyP5UMKTkA2uMw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ncsc.gov.uk; dmarc=pass action=none header.from=ncsc.gov.uk; dkim=pass header.d=ncsc.gov.uk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ncsc.gov.uk; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HPkJqsd6ytCLGmdqQUXJ7iszwNdwLTBVOwmJJ6jeq4A=; b=YppJ2TTAzNVkKirQJu8v4a6Z5F8ADS1KtanYRECBFs8m5XdAPXs5/O0GCjCec270dd6mBlwmBvPmYXt0S8XqnXJLIfye3LLechg5RlCRtq4NQvgJjOW06gKSLexhCknWF2CR7qMfv29r2QFZ4wJ59iBo8AiT94oF/Pr//PPUQHaO82rb5eqFdtbU5WTfYjL98si4VFNo+X/WG6QXmJ+6V/GhJd/WGG5uaxb/wYmYMse/25xu9c+M2/F+Vc2vapRhl6Xe+rKjQhY9e8wWf5UlomH7PlCloPLSA/zN4VeDYtBtZIulodw6nBuFMbtVbljAdsHC2ToMwpyzFxMtZtLTDQ==
Received: from LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:1df::13) by CWLP123MB2914.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:5a::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5654.14; Tue, 20 Sep 2022 15:45:37 +0000
Received: from LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM ([fe80::5085:db10:c921:9761]) by LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM ([fe80::5085:db10:c921:9761%6]) with mapi id 15.20.5632.021; Tue, 20 Sep 2022 15:45:36 +0000
From: Andrew S2 <andrew.s2@ncsc.gov.uk>
To: opsec WG <opsec@ietf.org>
Thread-Topic: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt
Thread-Index: AQHYxrfpvxwCoxE/lUe7XTAxq3QNJq3ofw4A
Date: Tue, 20 Sep 2022 15:45:36 +0000
Message-ID: <LO0P123MB4843233F0421E08E85F6F715E34C9@LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM>
References: <166299456569.40890.14626767404747814614@ietfa.amsl.com>
In-Reply-To: <166299456569.40890.14626767404747814614@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ncsc.gov.uk;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LO0P123MB4843:EE_|CWLP123MB2914:EE_
x-ms-office365-filtering-correlation-id: 81956de8-a4ef-4640-06e5-08da9b1f298a
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: IkNiQp/tUWXiSu3CNSKqlIgJROBYr0LVvF+IZbZ7J3dxrwKYBwlR7KR3DehszttS+Xq7G1HcsR0AdAWd5Dh2F1Hgr6ng/rD57Jq+sBhnxduSf4nsENDoryxB8QQTqEOtB5T6YauO7Rw2HTOa9pVSnWP1vmTueR74LUQqZ4QDrWEVNSTmmQIlkxkVDA/Cx81N+YOXcbpH5Vw8Fi8D8ES+s92teomdQ25u2kjNxlmdvJD1LrSuCIC4nWW6X4x/ypRQ2nyM0zc1eA9SEih8HE0I81A2z8YfJvupKUi/byPVAYSNN4XX3cFWOFpDpSsYrvj6ohQfO8VFuFRcgi9pqwlXK4Ogs6l1J1TluYhtTVvzVpHOFeBEuXudaDdMbqQgc/XpZ++1DbTWa25Aj7MTK0N+5gyfdnNYecjSfvHvrnM8vkDXrvM6DVRALkGi7kIx9FwQQ7CdzVWHYtU3sKB5kZpllVsaV7o6mK1c0Ix7PGPkSFxEKCHFHtX/5MapCK8yBltDRb3HDKHmDBqqbgbj/nfsfkJ/nxBs6vWddibPL6oP2UC6S8jyYvUg10IY5z+73Wn3nWLmJwtq3QyGbLgTP73YZLD0+l5S4qsPH0dZRTTD7tuneG/T65s1b3sJ/eFNXIJJef1jY4PXMhZzQreO5UJK8rUkKPHQrYQBHewVCgqkJUVHESP0XF1PLwePen+++jDT1At+GFyPL5ErxwdlF4OMtz3qrE4AZCmDo+2nkYbUj/N2ZhXumSrdvsQRRvUI4BE8+hT0gHo3ZSsdIF1YClBSxaLVOFIbqFrdW3Y0UfITsEU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230022)(4636009)(39860400002)(136003)(376002)(346002)(396003)(366004)(451199015)(966005)(478600001)(86362001)(8936002)(41300700001)(5660300002)(52536014)(71200400001)(8676002)(6916009)(316002)(66556008)(66476007)(66446008)(64756008)(33656002)(66946007)(76116006)(38070700005)(122000001)(82960400001)(55016003)(38100700002)(186003)(53546011)(7696005)(6506007)(26005)(9686003)(66574015)(83380400001)(2906002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: iygRNoq9ZaP9ncYjrPnrfHtiD3++EBzCXJeTk4oEhgpfIUSfG726pKYqu+0nLqxHoMYgzmuDiRMoSPKrjSTjJvu5AFeJT2NtPi24ffYUeRR+N0dilRF0rTArMebvVkCxBK/uBnm9fQ16eh8nwreS5s12+BDxqdUam8dQj9hZUd1TYVQKZqbFla5md7e+/d4zN8cUd+fap3nLlsmG201ads5JcLrLfS2llHN1BZTjBITRkRjoBpEH0lFBBkE+NBEgppVIFWnWip8oZNaMG47g00PTrjkcnNTiEf9unuhomcgevyc5UEHwwUic9HfIE2cNWsW1PlLKzBYsEw0eHuGmfz4kvZQVDoxe/37BSrxjcJYH4ouwO0Q/4HZO5SXtFK15oKH3QOLVLz3FYH5pKYkf/ooGiiQY6aLUMlhCuZhB8CEzwOlorm8860HbyKhNVBAegbyx10oAD3HSf7wwxavvM6rVhLT44DIhfCWxvZLuaSact2UfKaLNZhWkdwdfIUjXNjmfS/8FRhLWYwxd+vxx+SkLELyYtT1oVv12d87pmXQuVMRGEeQV1Ok93Xbi3kMNf11x05Fp/lzjHoh3/NpkQSearIrphF1W//b03+HDfsNNnEmwgPwz6ZgEwPdbcxD+DSue3prQ+IjK6p6cNmD6EUbTbfnIW5eF7oIrL6fgySI3EBqoZQ0w5rD5uP9JDLA0aeqZmLgXG3F1PebQ0aPUIYDh2hiJAdf74HgUx2eYZJYz+N0cNXJxbWzO8xCpJWrL/eZD1yKvB3m05VJW6utMZ6Xt26kxbhdmbKoG2zkYkAgnJRJTTUdkJyqgJCKEiZ+Vr8UF6uLITiRGfet6Owry2fnhY+HCcWkTKD2kfPm8FBhzeDQirGJX3TNbgRd/rG02OYIZZnwxGxhvOWy9dLIiFTEK6/TDaQgypc/BxfDJ7/bmL/tOcYVOvKuhQ+pe1h4mWzZw1J8ZlvMezKvZo/PtJ6ZtuMOb38MXchZSoCHGQ8yAa3ndCPz1MVI6J3FKXnr6mVFHVSSu0s4xauCJIXUlNDYkFLAR2WAhB8/6zYyWcFi4TEKe2wzPoNWpRfFDKZdhgPSsFlOmvScTz6t6pH9/wkbIgbqQVl8WeJh6zAfArTK7YRlCblgvsmgDuFH6+XD0S499upzA87Psay6TeGOdDXgktz0qZg0Lv5gvee56iI5t4oh5saS1i9E62OJuvrftH80hXaBEscBEI2LZpS13BnUNmmbgUxwVDQxLgYoO8duty3NaifSTfBiN24oBTS2CoZ4gand8n+q3RgyajYHGWBcw1ySFUysFLYyzSM+Xd56ICKEO2GSmUxqgVGZ9QxyprbCD3ooDPJNocgEAMd76xHxjmjPbD+EgjWYItYYskg9NlZMeCJeO0Sr3vdIlH5ilDYl1AV3dYEcqC7trJ277Y4EVoOT+wldha3eud3P5hzkuQRlK2+QePsaNUoPpWXXv7o9o7FfrgCRkHhvdD9/x8ncGM3cp1g5jKGL8hjGiiYe78KZIDAX0ypYD/sFbJCOH1KKC5uolMPOH1OMMJ1i2hn/Xuk1TT/+ODGF8kUuSiRJQm7rGPPPhaSfZNegHWG2j
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: ncsc.gov.uk
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 81956de8-a4ef-4640-06e5-08da9b1f298a
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Sep 2022 15:45:36.9080 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 14aa5744-ece1-474e-a2d7-34f46dda64a1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LWgVOLCuuKf0ZfadPz+UV1ktHuQCQCJsR1w8L1O9x8kONl2GjKkF9FcQlQi/VcCYwX5kCzBXInjw/sTu094+CQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CWLP123MB2914
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/_-1DHyXjoKBzfNs2_EjyAQ0ZlUo>
Subject: Re: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2022 15:45:48 -0000

A new version of our draft was uploaded to Datatracker last week which, we believe, addresses the comments raised during Working Group Last Call. Please do take a look and let us know if more clarification on those points would be helpful.

Thanks,
Andrew

-----Original Message-----
From: OPSEC <opsec-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org
Sent: 12 September 2022 15:56
To: i-d-announce@ietf.org
Cc: opsec@ietf.org
Subject: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure WG of the IETF.

        Title           : Indicators of Compromise (IoCs) and Their Role in Attack Defence
        Authors         : Kirsty Paine
                          Ollie Whitehouse
                          James Sellwood
                          Andrew Shaw
  Filename        : draft-ietf-opsec-indicators-of-compromise-02.txt
  Pages           : 29
  Date            : 2022-09-12

Abstract:
   Cyber defenders frequently rely on Indicators of Compromise (IoCs) to
   identify, trace, and block malicious activity in networks or on
   endpoints.  This draft reviews the fundamentals, opportunities,
   operational limitations, and best practices of IoC use.  It
   highlights the need for IoCs to be detectable in implementations of
   Internet protocols, tools, and technologies - both for the IoCs'
   initial discovery and their use in detection - and provides a
   foundation for new approaches to operational challenges in network
   security.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsec-indicators-of-compromise/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-opsec-indicators-of-compromise-02.html

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-indicators-of-compromise-02

Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts


_______________________________________________
OPSEC mailing list
OPSEC@ietf.org
https://www.ietf.org/mailman/listinfo/opsec
This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation. Refer any FOIA queries to ncscinfoleg@ncsc.gov.uk. All material is UK Crown Copyright (c)