[sacm] FW: Notes from terminology discussion

"Haynes, Dan" <dhaynes@mitre.org> Fri, 07 August 2015 17:17 UTC

Return-Path: <dhaynes@mitre.org>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D0F11B30B0 for <sacm@ietfa.amsl.com>; Fri, 7 Aug 2015 10:17:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.51
X-Spam-Level:
X-Spam-Status: No, score=-0.51 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9_JMKqNyBgn1 for <sacm@ietfa.amsl.com>; Fri, 7 Aug 2015 10:17:47 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (smtpvmsrv1.mitre.org [192.52.194.136]) by ietfa.amsl.com (Postfix) with ESMTP id BFECF1B30A9 for <sacm@ietf.org>; Fri, 7 Aug 2015 10:17:47 -0700 (PDT)
Received: from smtpvmsrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 1D79D6C00C9 for <sacm@ietf.org>; Fri, 7 Aug 2015 13:17:47 -0400 (EDT)
Received: from imshyb01.MITRE.ORG (imshyb01.mitre.org [129.83.29.2]) by smtpvmsrv1.mitre.org (Postfix) with ESMTP id 0F0916C00B3 for <sacm@ietf.org>; Fri, 7 Aug 2015 13:17:47 -0400 (EDT)
Received: from imshyb01.MITRE.ORG (129.83.29.2) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1044.25; Fri, 7 Aug 2015 13:17:47 -0400
Received: from na01-by2-obe.outbound.protection.outlook.com (10.140.19.249) by imshyb01.MITRE.ORG (129.83.29.2) with Microsoft SMTP Server (TLS) id 15.0.1044.25 via Frontend Transport; Fri, 7 Aug 2015 13:17:47 -0400
Received: from BLUPR09MB104.namprd09.prod.outlook.com (10.255.212.24) by BLUPR09MB104.namprd09.prod.outlook.com (10.255.212.24) with Microsoft SMTP Server (TLS) id 15.1.225.19; Fri, 7 Aug 2015 17:17:44 +0000
Received: from BLUPR09MB104.namprd09.prod.outlook.com ([10.255.212.24]) by BLUPR09MB104.namprd09.prod.outlook.com ([10.255.212.24]) with mapi id 15.01.0225.018; Fri, 7 Aug 2015 17:17:44 +0000
From: "Haynes, Dan" <dhaynes@mitre.org>
To: "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: Notes from terminology discussion
Thread-Index: AdDFW+X/BKOAO0a8TxePrtRZVbcEkgL2MIAQ
Date: Fri, 07 Aug 2015 17:17:44 +0000
Message-ID: <BLUPR09MB10430065876D48FBC6F6210A5730@BLUPR09MB104.namprd09.prod.outlook.com>
References: <BN1PR06MB437D4B8DA8EC56A907EED54A8810@BN1PR06MB437.namprd06.prod.outlook.com>
In-Reply-To: <BN1PR06MB437D4B8DA8EC56A907EED54A8810@BN1PR06MB437.namprd06.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=dhaynes@mitre.org;
x-originating-ip: [192.160.51.86]
x-microsoft-exchange-diagnostics: 1; BLUPR09MB104; 5:dgn+U64OshF7lr/lXuniiGyJgjWBj3z7Rn02I0RRpShAcqIJDCLB58FC3xlvYnphEG07vxRVgUVUEVFWbT5tXRokEkq3OGcYV8K+sskcKA31vwOWH5fZbO7/MGU7yMEl7udTNtctFMKloyr1aRvPnQ==; 24:vOkDJNbu6RYDQW5Hvk5fMjdj6FRAWuJ603ESh6mBDrex046IKhQDuzfwu+UW94IOlGy+YSIDQ/oQhcmmZoDovhOZqnvfx1hDnYhY3JI2nvA=; 20:7b0ZXUSEIXl1+q1ODIQ+riq8J5BTYMLVRy8zoIP3yhoz1MKmyjqrc/Edc1JHtUQeOqMJEiniv7hFELU77+7i9Q==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BLUPR09MB104;
x-microsoft-antispam-prvs: <BLUPR09MB1043C47E23C581765647BF6A5730@BLUPR09MB104.namprd09.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(5005006)(3002001); SRVR:BLUPR09MB104; BCL:0; PCL:0; RULEID:; SRVR:BLUPR09MB104;
x-forefront-prvs: 066153096A
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(377454003)(189002)(199003)(53754006)(13464003)(74316001)(5003600100002)(2900100001)(19580395003)(2950100001)(19580405001)(101416001)(46102003)(87936001)(2656002)(33656002)(62966003)(66066001)(64706001)(77156002)(450100001)(40100003)(5002640100001)(99286002)(106356001)(92566002)(4001540100001)(54356999)(81156007)(76176999)(122556002)(15975445007)(105586002)(2351001)(50986999)(77096005)(68736005)(76576001)(102836002)(189998001)(97736004)(107886002)(5001830100001)(110136002)(5001960100002)(5001860100001)(10400500002)(86362001)(2501003); DIR:OUT; SFP:1101; SCL:1; SRVR:BLUPR09MB104; H:BLUPR09MB104.namprd09.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: mitre.org does not designate permitted sender hosts)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Aug 2015 17:17:44.6389 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c620dc48-1d50-4952-8b39-df4d54d74d82
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR09MB104
X-OriginatorOrg: mitre.org
Archived-At: <http://mailarchive.ietf.org/arch/msg/sacm/kWxlnboHAXD87cned9WavwPZy5w>
Subject: [sacm] FW: Notes from terminology discussion
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Aug 2015 17:17:50 -0000

Just sharing some notes that were taken during an IETF 93 SACM working session.  Thanks to Lisa for putting them together!

-Danny

-----Original Message-----
From: Lisa Lorenzin [mailto:llorenzin@pulsesecure.net] 
Sent: Friday, July 24, 2015 6:20 PM
To: Jarrett Lu <jarrett.lu@oracle.com>; Adam Montville <adam.w.montville@gmail.com>; Haynes, Dan <dhaynes@mitre.org>; Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com>; Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Subject: Notes from terminology discussion

Hi all,

Here are the brief notes I took during the terminology discussion:

TERMINOLOGY NOTES:

relationships:
an asset instantiates an asset class or asset classes can use attributes collected from a target endpoint to map the target endpoint to an asset class or asset classes

an IP address can be any or all of: an attribute of an asset (hardware or software component), an attribute of a target endpoint, an attribute of <another container>

in the triple of subject, predicate, object - you MUST be able to use asset or endpoint as the subject, and you MUST also be able to use other subjects (i.e. asset and endpoint are the mandatory-to-implement subject, but implementers are not restricted to only asset and endpoint as subjects)

need a relationships section in the terminology draft since there's lots of glue information about how individual terms fit together which doesn't fall nicely under any single term definition

in a container, you can have other containers.  In a container, you can have more than one of any given container or any given AVP.
so the container network address contains the container IP address (along with other containers such as MAC address, and an extension point for future containers), and the container IP address might contain ipv4 address = $foo, ipv4 address = $bar, ipv6 address = $baz

container: network address
	container: IP address
		container: IPv4 address
			value

							Regards,

								Lisa


-- 
Lisa Lorenzin    /    Principal Solutions Architect
llorenzin@pulsesecure.net    /    919-384-7275

Pulse Secure    /    https://www.pulsesecure.net
Facebook: https://www.facebook.com/pulsesecure1
LinkedIn: https://www.linkedin.com/company/pulse-secure
Twitter: https://twitter.com/PulseSecure1