@techreport{savola-distsec-threat-model-01, number = {draft-savola-distsec-threat-model-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-savola-distsec-threat-model/01/}, author = {Pekka Savola}, title = {{Distributed Security Threat Model}}, pagetotal = 10, year = 2005, month = oct, day = 27, abstract = {The distributed security framework document describes an approach where hosts take greater responsibility for protecting against attacks on security vulnerabilities targeted at themselves. This memo analyzes the threat model of the distributed security approach, in particular pointing out areas which the mechanism cannot protect against. XXX: generic comment from JariA: "The main issue that I could see is that its still rather simple presentation of the issues, e.g. does not necessarily go as deep as some other ongoing work goes." XXX: generic comment from EKR: "I found the organization rather confusing. It seems to me like a lot of the material in the framework document would make more sense in the threat model. Without that context, it's fairly hard to understand what you're trying to accomplish." (Similar comment from others: addressing this would require significant(?) text duplication from the framework doc..)}, }