OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

openc2-actuator message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Proposed means to support (deny or allow) ICMP types


All,
 
Recall that we identified a gap in the SLPF.  As currently written, the SLPF does not support deny (or allow) traffic based on ICMP type. 
 
This is a direct paste from an issue on github located at:  https://github.com/oasis-tcs/openc2-apsc-stateless-packet-filter/issues/69
 
Here are three proposals: 
 
ONE:  Overload the ipv*_connection target. 
Add text in section 2.1.2.2
"Semantics / requirements as they pertain to ipv*_connection
 
TWO:  Create a new target type(s) for ICMP with properties of src address, dest address and ICMP type
 
THREE:  Expand the ip_connection to a 'six-tuple' vice five tuple to accommodate the ICMP type
 
Please provide your insights/ feedback in this matter. 
 
Also, it would be most helpful if you indicated your preferred approach or indicate that oyu have no preference
 
Thank you
 
VR
 
Joe B
 
Joe Brule
Engineering (Y2D122)
FNX-3, B4A335
410.854.4045
'Adnius ad retinedam puritem noster peciosus corporalis fluidorum…'
I welcome VSRE emails.  Learn more at http://vsre.info/
 
 
 


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]