OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: HTTP headers


Section 6.12.2 HTTP Request Extension states that the request_header property has type dictionary, and type dictionary (section 2.3) requires keys to be from the restricted character set of ASCII alphanumeric, hyphen, or underscore. This poses a problem for HTTP headers that have names outside of this character set. Although the standard headers conform to the restricted character set, custom headers may not. Preserving original the header names of malware traffics is critical for reporting and detecting the malware. (For one example, see https://community.rsa.com/t5/netwitness-discussions/plugx-apt-malware/td-p/460307, and the header name "ASH-1.0".)

What is the recommended practice for preserving the header names while conforming to the standard?
--
Ray Lischner
U.S. Contracting


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]