Skip to content

Security: Add threat model for OCM - #398

Open
mickenordin wants to merge 2 commits into
developfrom
kano-threat-model
Open

Security: Add threat model for OCM#398
mickenordin wants to merge 2 commits into
developfrom
kano-threat-model

Conversation

@mickenordin

Copy link
Copy Markdown
Member

During discussion at IETF 126 it became clear that being explicit about the threat model for OCM would be useful for implementers and reviewers alike. This patch introduces a threat model section in each of the OCM documents, as well as a new paragraph that calls out to the security section of load bearing RFCs that OCM leans on.

During discussion at IETF126 it became clear that being explicit
about the threat model for OCM would be useful for implementers
and reviewers alike. This patch introduces a threat model secion
in each of the OCM documents, as well as a new paragraph that
calls out to the security section of load bearing RFCs that OCM
leans on.
@MahdiBaghbani

Copy link
Copy Markdown
Member

I have been using lots of perplexity.ai to search for CVE and contexts for this 😄 It's a nice thing.

Will post my review soon.

@glpatcern

Copy link
Copy Markdown
Member

This is very welcome, and definitely in the direction of IETF Drafts. I read a bit of RFC 3552 and I can see we could even include some kind of attacker - impact - mitigation - residual risk table.
Will review it in the coming days, but just wanted to acknowledge the effort.

@mickenordin

Copy link
Copy Markdown
Member Author

This is very welcome, and definitely in the direction of IETF Drafts. I read a bit of RFC 3552 and I can see we could even include some kind of attacker - impact - mitigation - residual risk table. Will review it in the coming days, but just wanted to acknowledge the effort.

Oh, that is very nice, I had missed that RFC. Maybe we should even link to it?

Make it explicit that the Sending and Recieving OCM server as well
abortsprotocol servers are part of the trusted comput environment
and that the threat model assumes that the OCM server is not compromised.

The network, is untrusted as is other OCM servers on the network
@mickenordin

Copy link
Copy Markdown
Member Author

This is very welcome, and definitely in the direction of IETF Drafts. I read a bit of RFC 3552 and I can see we could even include some kind of attacker - impact - mitigation - residual risk table. Will review it in the coming days, but just wanted to acknowledge the effort.

Oh, that is very nice, I had missed that RFC. Maybe we should even link to it?

I edited the threat model with RFC 3552 in mind, in another separate commit. I am in favor of adding a tabulation of risks, mitigations and residual risks btw.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants