Real-time Inter-network Defense
RFC 6045, “Real-time Inter-network Defense”, is an Informational document published in November 2010 by K. Moriarty. It has been obsoleted by RFC 6545 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
Network security incidents, such as system compromises, worms, viruses, phishing incidents, and denial of service, typically result in the loss of service, data, and resources both human and system. Network providers and Computer Security Incident Response Teams need to be equipped and ready to assist in communicating and tracing security incidents with tools and procedures in place before the occurrence of an attack. Real-time Inter-network Defense (RID) outlines a proactive inter-network communication method to facilitate sharing incident handling data while integrating existing detection, tracing, source identification, and mitigation mechanisms for a complete incident handling solution. Combining these capabilities in a communication system provides a way to achieve higher security levels on networks. Policy guidelines for handling incidents are recommended and can be agreed upon by a consortium using the security recommendations and considerations.
RID has found use within the international research communities, but has not been widely adopted in other sectors. This publication provides the specification to those communities that have adopted it, and communities currently considering solutions for real-time inter-network defense. The specification may also accelerate development of solutions where different transports or message formats are required by leveraging the data elements and structures specified here. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 6045 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6044 Mapping and Interworking of Diversion Information between Diversion and History-Info Headers in the Session Initiation Protocol
- RFC 6046 Transport of Real-time Inter-network Defense Messages
- RFC 6047 iCalendar Message-Based Interoperability Protocol
- RFC 6042 Transport Layer Security Authorization Using KeyNote
- RFC 6048 Network News Transfer Protocol Additions to LIST Command
- RFC 6041 Forwarding and Control Element Separation Applicability Statement
- RFC 6040 Tunnelling of Explicit Congestion Notification
- RFC 6050 A Session Initiation Protocol Extension for the Identification of Services