[Smart] draft-mcfadden-smart-endpoint-taxonomy-for-cless-01.txt

Mark McFadden <mcfadden.ietf@gmail.com> Wed, 19 February 2020 16:02 UTC

Return-Path: <mcfadden.ietf@gmail.com>
X-Original-To: smart@ietfa.amsl.com
Delivered-To: smart@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AAA4F120806 for <smart@ietfa.amsl.com>; Wed, 19 Feb 2020 08:02:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ey7Z86lNQF8q for <smart@ietfa.amsl.com>; Wed, 19 Feb 2020 08:02:24 -0800 (PST)
Received: from mail-ot1-x336.google.com (mail-ot1-x336.google.com [IPv6:2607:f8b0:4864:20::336]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ECFAD120232 for <smart@irtf.org>; Wed, 19 Feb 2020 08:02:18 -0800 (PST)
Received: by mail-ot1-x336.google.com with SMTP id z9so618045oth.5 for <smart@irtf.org>; Wed, 19 Feb 2020 08:02:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=Ir3jIXvb0EEZdeFqbhKfAjh76/9a+ItxHEkGC9YDydI=; b=bPh7Q79AYhgxpj8FH8aLKQQRjcZ9CroHwaIKXNS1TWBauUrNgNmbqRITGCmQVm6ns+ Fi5hgArJG+wybS5ycYoW4X8oVFs9dCJ1+CxztIkz79BPSHTPWvYWGledXGxs2PB+M8p6 +qOoUnD5MrnW2pNOgfeJUJC3HJEjiCnI06GbLs/fAk+Uw6r5L+PSp9R/RvctHPHDM6tv UrW+mTCpfpfFmQs0Mbw8DISrjToN3o66fZM6RaKIeUD6ogea3KDW2NKLQsidNoCVN07+ 4eVPiQZR1psfaaMiRzYfqV+v6CE88qOzPwwltqwo40envT2TQodEx4gdbG223G4ntqeW 9LOg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=Ir3jIXvb0EEZdeFqbhKfAjh76/9a+ItxHEkGC9YDydI=; b=KUe41QpbyqODi/orLEI937/ke2On55lGVQ0C9YLdWf31jXCIPDFdrIPcp6kN8wiO9I AN4zPf3hbzqO0MbxX7d4KfBDJwib8JlNCLhdCqXhb/CF8D2KeU6B94HVmR2BNI6IO3n8 1pobrLA2phgh9KLnwWnl49Q3ZEjniqZD+JoqjQT8WAcbOwNqAq6qSWGdmP56LePrVQUu g9JxfKW4hpETso2lmoqJG+nNmJVDmvHIHrZ8fZhplhwwQWJK6HcvuBXDr39bU6CNYk2X w1hO0EWeNhnA0OnID2E+nJaH2wIQ8x0iwst00xt5wAeR/dbD00+x90Ahi5qmO59Jdlgb Q7Qw==
X-Gm-Message-State: APjAAAWeCTmWfSUxzzzkNm83VFe0LEweTvom/D6fbsfYHZpDvuOckcZ9 k4BXtaJGRafTkRgFoDcThXLTf8TESCSbUqT0+P30rw==
X-Google-Smtp-Source: APXvYqw9UYGvcdPs6Scqldc4RC4TpgoQOSwHNINywH6g62dmy2XoBcg1Bhr+KSC72Sepsd9fdCVyrcAw1JllM1c0RpA=
X-Received: by 2002:a9d:2c2:: with SMTP id 60mr20069050otl.208.1582128137912; Wed, 19 Feb 2020 08:02:17 -0800 (PST)
MIME-Version: 1.0
From: Mark McFadden <mcfadden.ietf@gmail.com>
Date: Wed, 19 Feb 2020 10:02:06 -0600
Message-ID: <CAFYLZbFMYLbYZbA_ZKeR5uD3=iPQrS6MVDwcYc9JD7eCPsBtiA@mail.gmail.com>
To: smart@irtf.org
Content-Type: multipart/alternative; boundary="000000000000a643c2059eefe981"
Archived-At: <https://mailarchive.ietf.org/arch/msg/smart/r5BG3gg4NkDOkoC64jQ4D0oiIts>
Subject: [Smart] draft-mcfadden-smart-endpoint-taxonomy-for-cless-01.txt
X-BeenThere: smart@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Stopping Malware And Researching Threats <smart.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/smart>, <mailto:smart-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smart/>
List-Post: <mailto:smart@irtf.org>
List-Help: <mailto:smart-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/smart>, <mailto:smart-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Feb 2020 16:02:27 -0000

All:

Thanks to those who provided comments on the first draft of this. I would
be very appreciative of any comments on the new draft, in particular on the
approach toward a hierarchy of taxonomy presented here.
I also will post this to the "Model T" discussion as an attempt to describe
the endpoints which make up a new threat model. A discussion on "Model T"
last week seemed to indicate some disagreement over just how different the
threat landscape is since the time of RFC3552,  I'm hoping an accurate
taxonomy of the endpoints might help in that discussion.

mark