The Intrusion Detection Exchange Protocol (IDXP)
Voir toute la rfc dans une seule page
Page : 25 / 28
Télécharger le PDF
Auteur(s) :
B. Feinstein,
G. Matthews
Classé sous :
Security,
Ids,
Beep,
Intrusion detection,
Intrusion,
Idmef,
Security protocol,
Secure protocol,
Secure exchange
RFC 4767 IDXP March 2007
11. Security Considerations
The IDXP profile is a profile of BEEP. In BEEP, transport security,
user authentication, and data exchange are orthogonal. Refer to
Section 9 of [4] for a discussion of this. It is strongly
recommended that those wanting to use the IDXP profile initially
negotiate a BEEP security profile between the peers that offers the
required security properties. The TLS profile SHOULD be used to
provide for transport security. See Section 5 for a discussion of
how IDXP fulfills the IDWG communications protocol requirements.
See Section 2.4 for a discussion of the trust model.
11.1. Use of the TUNNEL Profile
See Section 5 for IDXP's requirements on application-layer tunneling
and the TUNNEL profile specifically. See Section 7 of [3] for a
discussion of the security considerations inherent in the use of the
TUNNEL profile.
11.2. Use of Underlying Security Profiles
At present, the TLS profile is the only BEEP security profile known
to meet all of the requirements set forth in Section 5 of [5]. When
securing a BEEP session with the TLS profile, the
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA cipher suite offers an acceptable
level of security. See Section 5 for a discussion of how IDXP
fulfills the IDWG communications requirements through the use of an
underlying security profile.
12. IANA Considerations
The IANA registered "idxp" as a TCP port number as specified in
Section 8.2.
The IANA maintains a list of:
IDXP options, see Section 7.
For this list, the IESG is responsible for assigning a designated
expert to review the specification prior to the IANA making the
assignment. As a courtesy to developers of non-standards track IDXP
options, the mailing list idxp-discuss@lists.idxp.org may be used to
solicit commentary.
IANA made the registrations specified in Sections 8.3 and 8.4.
Feinstein & Matthews Experimental [Page 25]