Chapter5SECURITYREQUIREMENTS
5.1.2.8FDP_IFF.1(1)Simplesecurityattributes(unauthenticated)
FDP_IFF.1.1TheTSFshallenforcethe[UNAUTHENTICATEDSFP]basedonthe
followingtypesofsubjectandinformationsecurityattributes:
[securitysubjectattributes:
1.IPnetworkaddressandportofsourcesubject;
2.IPnetworkaddressandportofdestinationsubject;
3.transportlayerprotocolandtheiragsandattributes(UDP ,TCP);
4.networklayerprotocol(IP ,ICMP);
5.interfaceonwhichtrafcarrivesanddeparts;
6.routingprotocols(BGPv4,OSPFv2,IS-IS,RIPv2)andtheircongurationandstate;
and
7.controltrafcandtrafcthreshold].
ApplicationNote:theTOEonlyacceptsroutinginformationfromotherrouterswithtrusted
IPsconguredbytheadministrators.
FDP_IFF.1.2TheTSFshallpermitaninformationowbetweenacontrolledsubjectand
controlledinformationviaacontrolledoperationifthefollowingruleshold:
1.[a.theinformationsecurityattributesmatchtheattributesinalteringrule(contained
intheinformationowpolicyrulesetdenedbytheAdministrator)accordingtothe
followingalgorithm:
lFirstmatch.Whenmultiplepolicynamesarespecied,thepoliciesshallbe
executedintheordertheyarespecied.Therstpolicythatmatchesisapplied;
theselectedinformationowpolicyrulespeciesthattheinformationowisto
bepermitted]
2.thepresumedaddressofthesourcesubject,inthepacket,isconsistentwiththe
networkinterfaceitarriveson;
3.thepresumedaddressofthedestinationsubject,inthepacket,canbemappedtoa
nexthop;
4.thesecurityattributesofthepacketmatchestheconguredroute-mappolicy
(containedintheinformationowpolicyrulesetdenedbytheAdministrator)andit
canbemappedtothenexthop].
ApplicationNote:A“nexthop”isthenextroutertowhichapacketissentfromanygiven
routerasittraversesanetworkonitsjourneytoitsnaldestination.Intheeventthatthe
packetisatthenalrouterinitsjourney,thenexthopisthenaldestination.
FDP_IFF.1.3TheTSFshallenforcethe[followingrules:
1.whentheup-sendingowratefromthenetworkinterfaceexceedsthecongured
threshold,theexceededtrafcwillbedropped(Anti-DoS);
2.whentheoutgoinginterfaceofthesourceroutingpacketisdifferentfromtheingoing
interface,thepacketwillbedropped.(URPF)
3.whenthesemi-connectionstatisticsinformationoftheTCPSYNoodexceeds
conguredthreshold,theTOEsuppressestheseattacks.]
5-5
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION