Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery

From
Trey Darley
Date
2015-10-31T08:38:00+00:00
ID
Thread
Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery
On 30.10.2015 21:28:38, Jordan, Bret wrote: >
> TAXII servers. So therefore the TAXII servers need to be hardened
> with good coding standards and have controls put around them.
>
It would be worth threat modeling the TAXII 2.0 architecture (once the spec's closer to completion) with an eye towards generating a TAXII 2.0 security best practices guide for implementers as an OASIS work product.

--
Cheers, Trey

--
Trey Darley Senior Security Engineer 4DAA 0A88 34BC 27C9 FD2B  A97E D3C6 5C74 0FB7 E430 Soltra
An FS-ISAC & DTCC Company www.soltra.com -- "With sufficient thrust, pigs fly just fine. However, this is not necessarily a good idea. It is hard to be sure where they are going to land, and it could be dangerous sitting under them as they fly overhead." --RFC 1925
Attachment:
signature.asc
Description:  PGP signature