Internet Engineering Task Force
Extended INCident Handling Working Group (INCH)
http://www.cert.org/ietf/inch/inch_interim_2004.html
12:00 – 16:00 Sunday, June 13 2004 Interim Meeting Budapest, Hungary
Roman Danyliw, <rdd@cert.org>
Extended INCident Handling Working Group (INCH) - - PowerPoint PPT Presentation
Internet Engineering Task Force Extended INCident Handling Working Group (INCH) http://www.cert.org/ietf/inch/inch_interim_2004.html 12:00 16:00 Sunday, June 13 2004 Interim Meeting Budapest, Hungary Roman Danyliw, <rdd@cert.org>
http://www.cert.org/ietf/inch/inch_interim_2004.html
Roman Danyliw, <rdd@cert.org>
June 13. 2004 Interim Meeting 2004 2
12:00 - 13:30 SESSION 1
– <http://www.cert.org/ietf/inch/interim04/ietf-interim2004-inch-agenda.pdf>
– <http://www.cert.org/ietf/inch/interim04/ietf-interim2004-inch-rid.pdf>
– <http://www.cert.org/ietf/inch/interim04/ietf-interim2004-inch-dm.pdf>
13:30 - 14:00 Coffee Break 14:00 - 15:30 SESSION 2
– JPCERT/CC Scanning Project
– Vulnerabilities and Exploits Description Exchange Format (VEDEF)
June 13. 2004 Interim Meeting 2004 3
June 13. 2004 Interim Meeting 2004 4
(http://www.ietf.org/html.charters/inch-chart.html)
– a CSIRT and its constituency (e.g., users, customers, trusted reporters) which reports system misuse; – a CSIRT and parties involved in an incident investigation (e.g., attacking site); and – collaborating CSIRTs sharing information.
June 13. 2004 Interim Meeting 2004 5
June 13. 2004 Interim Meeting 2004 6
– Transport representation
– Completeness for typical CSIRT data exchange
– Provide an explicit protocol – Optimize for storage – Optimize for human readability
June 13. 2004 Interim Meeting 2004 7
IODEF
Incident DB Incident DB Translator Translator
June 13. 2004 Interim Meeting 2004 8
– Format for Incident Exchange (FINE)
– http://www.cert.org/ietf/inch/docs/draft-ietf-inch-requirements-03.txt
– Incident Object Description Exchange Format (IODEF)
– http://www.cert.org/ietf/inch/docs/draft-ietf-inch-iodef-02.txt
– Real-time Internet-network Defense (RID)
– http://www.ietf.org/internet-drafts/draft-ietf-inch-rid-00.txt
– http://www.ietf.org/internet-drafts/draft-ietf-inch-implement-00.txt
June 13. 2004 Interim Meeting 2004 9
June 13. 2004 Interim Meeting 2004 10
June 13. 2004 Interim Meeting 2004 11
June 13. 2004 Interim Meeting 2004 12
June 13. 2004 Interim Meeting 2004 13
– All work starts as an I-D
– Standards – Informational – Best Common Practice (BCP)
– Working group – Area director (AD) – IETF member body – Internet Engineering Steering Group (IESG)
June 13. 2004 Interim Meeting 2004 14
(draft-ietf-inch-requirements-03)
(draft-ietf-inch-iodef-02)
(draft-ietf-inch-rid-00)
(draft-ietf-inch-implement-00)
June 13. 2004 Interim Meeting 2004 15
– Slippage till August 04?
– Slippage till Nov 04?
– Slippage till Nov 04?
– Slippage depends on data model
June 13. 2004 Interim Meeting 2004 16
http://listserv.surfnet.nl/archives/inch.html
send mail to listserv@nic.surfnet.nl with "subscribe inch <first name> <last name>" in the body