NetSecOPEN Testing Methodologies
NetSecOPEN has used multiple methodologies since testing began in 2020. This page will document all official methodology versions used or have been used by NetSecOPEN.
This page will document version 1.0, which was RFC 9411 along with an appmix, vulnerability sets, malware set and a few evasion techniques, and Version 1.1, starting early 2024, which included modifications to all of the test sets plus adoption of Certification Body decisions.
For all preliminary methodologies followed prior to 2023, they used the current draft version of what would become RFC 9411. We will not be documenting those methodologies here.
NetSecOPEN - Methodology - 1.0
The NetSecOPEN Methodology - 1.0 is the same as RFC 9411: Benchmarking Methodology for Network Security Device Performance, which is authored by members of NetSecOPEN. There is no difference between this methodology and RFC 9411.
The version of the methodology presented is 1.0:
Published: March 15, 2023.
<Link to: NetSecOpen - Methodology - 1.0.html> (doesn’t exist yet)
Additions / Changes to RFC 9411: None
NetSecOPEN - Methodology - 1.1
The NetSecOPEN Methodology - 1.1 is based on RFC 9411: Benchmarking Methodology for Network Security Device Performance which is authored by members of NetSecOPEN. The RFC is mostly static with some errata allowed, but in order to be more dynamic in updates and changes to what is in the RFC, this methodology will build on top of RFC 9411 as a base.
The version of the methodology presented is 1.1:
Published: Nov. 3, 2023
Updated: May 15, 2024
<Link to: NetSecOpen - Methodology - 1.1.html> (doesn’t exist yet)
Additions / Changes to RFC 9411:
April 3, 2023 - Augment RFC 9411 - A.3.2 with NETSECOPEN-CERT-001 to expand the definition of allowable background traffic and what CVEs will be used to test security under load.
April 3, 2023 - Augment RFC 9411 - 4.2.1 with NETSECOPEN-CERT-003 (003 is the correct number but these dont exist yet) add an all/public/private CVE set for testing.
April 3, 2023 - Augment RFC 9411 - 4.2.1 with NETSECOPEN-CERT-004 (004 doesn’t exist) add new threat types for malware, and evasions.
April 3, 2023 - Augment RFC 9411 - 4.3.1.4 with NETSECOPEN-CERT-005 (005 doesn’t exist) allow for new ciphers