Re: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt
Andrew S2 <andrew.s2@ncsc.gov.uk> Tue, 20 September 2022 15:45 UTC
Return-Path: <andrew.s2@ncsc.gov.uk>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3CC78C14F728 for <opsec@ietfa.amsl.com>; Tue, 20 Sep 2022 08:45:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.913
X-Spam-Level:
X-Spam-Status: No, score=-7.913 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.233, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ncsc.gov.uk
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4Ax-vaEuiE2x for <opsec@ietfa.amsl.com>; Tue, 20 Sep 2022 08:45:44 -0700 (PDT)
Received: from GBR01-LO2-obe.outbound.protection.outlook.com (mail-lo2gbr01on2091.outbound.protection.outlook.com [40.107.10.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ACC35C152562 for <opsec@ietf.org>; Tue, 20 Sep 2022 08:45:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LtLdwQYruQjnonTmYd7/CKIhiX6f7zXP0Npu04etAYNKoKS0eofT4OAohM5xgmwH+00suKA9GOCX00uz6M0fTrq02rL7Nrnom9EnCfVp05/ncYR/61XAiou7PzU16jkAqyQdEGzqYHaP2C1M1zWk3FHm5vFx5hAVdaKwlgFOZ3mxM1+GzKa2XQFF5JTePZgEosfP+NzMgVwwkDfb5q9uo5qnd6E93p2WJJjqMsCKT+lM91Dg4wPWcYyK0oK42KP/sK/+dmgfoazOtCDrbmFuu6c4VJYj6de02HqO7dYuV4p8ksb6Ki+1Zas7T4BkFvgYvnPmT5iKv+KcOnOZOPzlQA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=HPkJqsd6ytCLGmdqQUXJ7iszwNdwLTBVOwmJJ6jeq4A=; b=j8Ff0Od7HKjwzSTxbnK6eJvDuvKF0Lk82J+45b1KvSRoNVpE0vGwgJG+4bSxldjtW3cZe59E4UT7EWISFyk9oONayYCdaUbLktw/2r2/5LoP/ZiiRqKtBvV0s/fh4CbGYQufvyDzTjfWHT3QvWMTF2q4hofgkMSdll0XKMgEwUJTT0LVECNh2ViMVFPtNMvjSzDvRJMaQaqL9nUMH24npxfGemu/SzbsgIiNUjpJSYhoxPuo/f4qKguVmpsT2gFdUvuQdUHK6w0jEunRcT+kn4noLaO7Bo2tXKMl2UFPfCGjFYBEuGyrcivliRf6PjHt9xD03MbAAyP5UMKTkA2uMw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ncsc.gov.uk; dmarc=pass action=none header.from=ncsc.gov.uk; dkim=pass header.d=ncsc.gov.uk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ncsc.gov.uk; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HPkJqsd6ytCLGmdqQUXJ7iszwNdwLTBVOwmJJ6jeq4A=; b=YppJ2TTAzNVkKirQJu8v4a6Z5F8ADS1KtanYRECBFs8m5XdAPXs5/O0GCjCec270dd6mBlwmBvPmYXt0S8XqnXJLIfye3LLechg5RlCRtq4NQvgJjOW06gKSLexhCknWF2CR7qMfv29r2QFZ4wJ59iBo8AiT94oF/Pr//PPUQHaO82rb5eqFdtbU5WTfYjL98si4VFNo+X/WG6QXmJ+6V/GhJd/WGG5uaxb/wYmYMse/25xu9c+M2/F+Vc2vapRhl6Xe+rKjQhY9e8wWf5UlomH7PlCloPLSA/zN4VeDYtBtZIulodw6nBuFMbtVbljAdsHC2ToMwpyzFxMtZtLTDQ==
Received: from LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM (2603:10a6:600:1df::13) by CWLP123MB2914.GBRP123.PROD.OUTLOOK.COM (2603:10a6:400:5a::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5654.14; Tue, 20 Sep 2022 15:45:37 +0000
Received: from LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM ([fe80::5085:db10:c921:9761]) by LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM ([fe80::5085:db10:c921:9761%6]) with mapi id 15.20.5632.021; Tue, 20 Sep 2022 15:45:36 +0000
From: Andrew S2 <andrew.s2@ncsc.gov.uk>
To: opsec WG <opsec@ietf.org>
Thread-Topic: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt
Thread-Index: AQHYxrfpvxwCoxE/lUe7XTAxq3QNJq3ofw4A
Date: Tue, 20 Sep 2022 15:45:36 +0000
Message-ID: <LO0P123MB4843233F0421E08E85F6F715E34C9@LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM>
References: <166299456569.40890.14626767404747814614@ietfa.amsl.com>
In-Reply-To: <166299456569.40890.14626767404747814614@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ncsc.gov.uk;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: LO0P123MB4843:EE_|CWLP123MB2914:EE_
x-ms-office365-filtering-correlation-id: 81956de8-a4ef-4640-06e5-08da9b1f298a
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: IkNiQp/tUWXiSu3CNSKqlIgJROBYr0LVvF+IZbZ7J3dxrwKYBwlR7KR3DehszttS+Xq7G1HcsR0AdAWd5Dh2F1Hgr6ng/rD57Jq+sBhnxduSf4nsENDoryxB8QQTqEOtB5T6YauO7Rw2HTOa9pVSnWP1vmTueR74LUQqZ4QDrWEVNSTmmQIlkxkVDA/Cx81N+YOXcbpH5Vw8Fi8D8ES+s92teomdQ25u2kjNxlmdvJD1LrSuCIC4nWW6X4x/ypRQ2nyM0zc1eA9SEih8HE0I81A2z8YfJvupKUi/byPVAYSNN4XX3cFWOFpDpSsYrvj6ohQfO8VFuFRcgi9pqwlXK4Ogs6l1J1TluYhtTVvzVpHOFeBEuXudaDdMbqQgc/XpZ++1DbTWa25Aj7MTK0N+5gyfdnNYecjSfvHvrnM8vkDXrvM6DVRALkGi7kIx9FwQQ7CdzVWHYtU3sKB5kZpllVsaV7o6mK1c0Ix7PGPkSFxEKCHFHtX/5MapCK8yBltDRb3HDKHmDBqqbgbj/nfsfkJ/nxBs6vWddibPL6oP2UC6S8jyYvUg10IY5z+73Wn3nWLmJwtq3QyGbLgTP73YZLD0+l5S4qsPH0dZRTTD7tuneG/T65s1b3sJ/eFNXIJJef1jY4PXMhZzQreO5UJK8rUkKPHQrYQBHewVCgqkJUVHESP0XF1PLwePen+++jDT1At+GFyPL5ErxwdlF4OMtz3qrE4AZCmDo+2nkYbUj/N2ZhXumSrdvsQRRvUI4BE8+hT0gHo3ZSsdIF1YClBSxaLVOFIbqFrdW3Y0UfITsEU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230022)(4636009)(39860400002)(136003)(376002)(346002)(396003)(366004)(451199015)(966005)(478600001)(86362001)(8936002)(41300700001)(5660300002)(52536014)(71200400001)(8676002)(6916009)(316002)(66556008)(66476007)(66446008)(64756008)(33656002)(66946007)(76116006)(38070700005)(122000001)(82960400001)(55016003)(38100700002)(186003)(53546011)(7696005)(6506007)(26005)(9686003)(66574015)(83380400001)(2906002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: iygRNoq9ZaP9ncYjrPnrfHtiD3++EBzCXJeTk4oEhgpfIUSfG726pKYqu+0nLqxHoMYgzmuDiRMoSPKrjSTjJvu5AFeJT2NtPi24ffYUeRR+N0dilRF0rTArMebvVkCxBK/uBnm9fQ16eh8nwreS5s12+BDxqdUam8dQj9hZUd1TYVQKZqbFla5md7e+/d4zN8cUd+fap3nLlsmG201ads5JcLrLfS2llHN1BZTjBITRkRjoBpEH0lFBBkE+NBEgppVIFWnWip8oZNaMG47g00PTrjkcnNTiEf9unuhomcgevyc5UEHwwUic9HfIE2cNWsW1PlLKzBYsEw0eHuGmfz4kvZQVDoxe/37BSrxjcJYH4ouwO0Q/4HZO5SXtFK15oKH3QOLVLz3FYH5pKYkf/ooGiiQY6aLUMlhCuZhB8CEzwOlorm8860HbyKhNVBAegbyx10oAD3HSf7wwxavvM6rVhLT44DIhfCWxvZLuaSact2UfKaLNZhWkdwdfIUjXNjmfS/8FRhLWYwxd+vxx+SkLELyYtT1oVv12d87pmXQuVMRGEeQV1Ok93Xbi3kMNf11x05Fp/lzjHoh3/NpkQSearIrphF1W//b03+HDfsNNnEmwgPwz6ZgEwPdbcxD+DSue3prQ+IjK6p6cNmD6EUbTbfnIW5eF7oIrL6fgySI3EBqoZQ0w5rD5uP9JDLA0aeqZmLgXG3F1PebQ0aPUIYDh2hiJAdf74HgUx2eYZJYz+N0cNXJxbWzO8xCpJWrL/eZD1yKvB3m05VJW6utMZ6Xt26kxbhdmbKoG2zkYkAgnJRJTTUdkJyqgJCKEiZ+Vr8UF6uLITiRGfet6Owry2fnhY+HCcWkTKD2kfPm8FBhzeDQirGJX3TNbgRd/rG02OYIZZnwxGxhvOWy9dLIiFTEK6/TDaQgypc/BxfDJ7/bmL/tOcYVOvKuhQ+pe1h4mWzZw1J8ZlvMezKvZo/PtJ6ZtuMOb38MXchZSoCHGQ8yAa3ndCPz1MVI6J3FKXnr6mVFHVSSu0s4xauCJIXUlNDYkFLAR2WAhB8/6zYyWcFi4TEKe2wzPoNWpRfFDKZdhgPSsFlOmvScTz6t6pH9/wkbIgbqQVl8WeJh6zAfArTK7YRlCblgvsmgDuFH6+XD0S499upzA87Psay6TeGOdDXgktz0qZg0Lv5gvee56iI5t4oh5saS1i9E62OJuvrftH80hXaBEscBEI2LZpS13BnUNmmbgUxwVDQxLgYoO8duty3NaifSTfBiN24oBTS2CoZ4gand8n+q3RgyajYHGWBcw1ySFUysFLYyzSM+Xd56ICKEO2GSmUxqgVGZ9QxyprbCD3ooDPJNocgEAMd76xHxjmjPbD+EgjWYItYYskg9NlZMeCJeO0Sr3vdIlH5ilDYl1AV3dYEcqC7trJ277Y4EVoOT+wldha3eud3P5hzkuQRlK2+QePsaNUoPpWXXv7o9o7FfrgCRkHhvdD9/x8ncGM3cp1g5jKGL8hjGiiYe78KZIDAX0ypYD/sFbJCOH1KKC5uolMPOH1OMMJ1i2hn/Xuk1TT/+ODGF8kUuSiRJQm7rGPPPhaSfZNegHWG2j
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: ncsc.gov.uk
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: LO0P123MB4843.GBRP123.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 81956de8-a4ef-4640-06e5-08da9b1f298a
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Sep 2022 15:45:36.9080 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 14aa5744-ece1-474e-a2d7-34f46dda64a1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LWgVOLCuuKf0ZfadPz+UV1ktHuQCQCJsR1w8L1O9x8kONl2GjKkF9FcQlQi/VcCYwX5kCzBXInjw/sTu094+CQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CWLP123MB2914
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/_-1DHyXjoKBzfNs2_EjyAQ0ZlUo>
Subject: Re: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2022 15:45:48 -0000
A new version of our draft was uploaded to Datatracker last week which, we believe, addresses the comments raised during Working Group Last Call. Please do take a look and let us know if more clarification on those points would be helpful. Thanks, Andrew -----Original Message----- From: OPSEC <opsec-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org Sent: 12 September 2022 15:56 To: i-d-announce@ietf.org Cc: opsec@ietf.org Subject: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure WG of the IETF. Title : Indicators of Compromise (IoCs) and Their Role in Attack Defence Authors : Kirsty Paine Ollie Whitehouse James Sellwood Andrew Shaw Filename : draft-ietf-opsec-indicators-of-compromise-02.txt Pages : 29 Date : 2022-09-12 Abstract: Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This draft reviews the fundamentals, opportunities, operational limitations, and best practices of IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies - both for the IoCs' initial discovery and their use in detection - and provides a foundation for new approaches to operational challenges in network security. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-ietf-opsec-indicators-of-compromise/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-opsec-indicators-of-compromise-02.html A diff from the previous version is available at: https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-indicators-of-compromise-02 Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts _______________________________________________ OPSEC mailing list OPSEC@ietf.org https://www.ietf.org/mailman/listinfo/opsec This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation. Refer any FOIA queries to ncscinfoleg@ncsc.gov.uk. All material is UK Crown Copyright (c)
- [OPSEC] I-D Action: draft-ietf-opsec-indicators-o… internet-drafts
- Re: [OPSEC] I-D Action: draft-ietf-opsec-indicato… Andrew S2