news
Standards/Consortia: Internet Protocol Version 8 (IPv8) and NIST Changes to CVE Scope
-
IETF ☛ draft-thain-ipv8-01 - Internet Protocol Version 8 (IPv8)
Internet Protocol Version 8 (IPv8) is a managed network protocol suite that transforms how networks of every scale -- from home networks to the global internet -- are operated, secured, and monitored. Every manageable element in an IPv8 network is authorised via OAuth2 JWT tokens served from a local cache. Every service a device requires is delivered in a single DHCP8 lease response. Every packet transiting to the internet is validated at egress against a DNS8 lookup and a WHOIS8 registered active route. Network telemetry, authentication, name resolution, time synchronisation, access control, and translation are unified into a single coherent Zone Server platform.
IPv4 is a proper subset of IPv8. An IPv8 address with the routing prefix field set to zero is an IPv4 address. No existing device, application, or network requires modification. The suite is 100% backward compatible. There is no flag day and no forced migration at any layer.
IPv8 also resolves IPv4 address exhaustion. Each Autonomous System Number (ASN) holder receives 4,294,967,296 host addresses. The global BGP8 routing table is structurally bounded by ASN count rather than prefix count. WHOIS8 is a critical infrastructure service underpinning this model.
This document is one of the companion specifications: [...]
-
Scoop News Group ☛ NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
NIST said it will only prioritize analysis for CVEs that appear in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, software used in the federal government and critical software defined under Executive Order 14028.
-
The Record ☛ NIST to limit work on CVE entries as submissions surge
Starting on Wednesday, NIST will only enrich CVEs that appear in a federal catalog of exploited vulnerabilities organized by the Cybersecurity and Infrastructure Security Agency (CISA). Bugs added to the catalog will be enriched within one day of notice from CISA.
CVEs in products used by the federal government and software deemed “critical” will also be enriched by NIST.