NetSecOPEN Testing Methodologies
NetSecOPEN has used multiple methodologies since testing began in 2020. This page will document version 1.0, which was RFC 9411 along with an appmix, vulnerability sets, malware set and a few evasion techniques, and Version 1.1, starting early 2024, which included modifications to all of the test sets plus adoption of Certification Body decisions.
For all methodologies followed prior to 2023, they followed the current draft version of what would become RFC 9411. We will not be documenting those methodologies here.
Test Methodology v1.0
The NetSecOPEN methodology is based on RFC 9411 which is authored by members of NetSecOPEN. The RFC is mostly static with some errata allowed, but in order to be more dynamic in updates and changes to what is in the RFC, this methodology will build on top of RFC 9411 as a base.
The version of the methodology presented is 1.0:
Published: March 15, 2023.
Definitions:
NetSecOPEN - App Mix - v 1.0 for the definition of its application mixes.
NetSecOPEN - CVE Master - v 1.0 for the definition of the full set of CVEs
NetSecOPEN - CVE Public - v 1.0 for the definition of the public set of CVEs
NetSecOPEN - Malware - v 1.0 for the definition of the malware set
NetSecOPEN - Evasion - v 1.0 for the definition of the evasions used (not sure if we had this)
NetSecOPEN - Ciphers - v 1.0 for the definition of the ciphers used (not sure if we had this)
Additions / Changes to RFC 9411: None
Test Methodology v1.1
The NetSecOPEN methodology is based on RFC 9411 which is authored by members of NetSecOPEN. The RFC is mostly static with some errata allowed, but in order to be more dynamic in updates and changes to what is in the RFC, this methodology will build on top of RFC 9411 as a base.
The version of the methodology presented is 1.1:
Published: Nov. 3, 2023
Updated: May 15, 2024
Definitions:
NetSecOPEN - App Mix - v 1.1 for the definition of its application mixes.
NetSecOPEN - CVE Master - v 1.1 for the definition of the full set of CVEs
NetSecOPEN - CVE Public - v 1.1 for the definition of the public set of CVEs
NetSecOPEN - Malware - v 1.1 for the definition of the malware set
NetSecOPEN - Evasion - v 1.1 for the definition of the evasions used
NetSecOPEN - Ciphers - v 1.1 for the definition of the ciphers used
Additions / Changes to RFC 9411:
April 3, 2023 - Augment RFC 9411 - A.3.2 with NETSECOPEN-CERT-001 to expand the definition of allowable background traffic.
May 15, 2024 - Augment RFC 9411 - A.5 with NETSECOPEN-CERT-002, removed CVE 2016-3368 from the master and public CVE lists. This CVE result will be ignored in any future tests.