2018
DOI: 10.17487/rfc8322
|View full text |Cite
|
Sign up to set email alerts
|

Resource-Oriented Lightweight Information Exchange (ROLIE)

Abstract: This document defines a resource-oriented approach for security automation information publication, discovery, and sharing. Using this approach, producers may publish, share, and exchange representations of software descriptors, security incidents, attack indicators, software vulnerabilities, configuration checklists, and other security automation information as web-addressable resources.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
5
0

Year Published

2018
2018
2021
2021

Publication Types

Select...
3
1

Relationship

0
4

Authors

Journals

citations
Cited by 4 publications
(5 citation statements)
references
References 12 publications
0
5
0
Order By: Relevance
“…As of now, the ontology specification is still in early stages. Using the Resource-Oriented Lightweight Information Exchange (ROLIE) [66] format for incident response standardization is another option. The IETF RFC 8322 defines ROLIE to support exchange of various types of security information.…”
Section: G Other Approachesmentioning
confidence: 99%
“…As of now, the ontology specification is still in early stages. Using the Resource-Oriented Lightweight Information Exchange (ROLIE) [66] format for incident response standardization is another option. The IETF RFC 8322 defines ROLIE to support exchange of various types of security information.…”
Section: G Other Approachesmentioning
confidence: 99%
“…The Resource Orientated Lightweight Information Exchange (ROLIE) protocol [8] provides a standardized mechanism for an SCAP Content Repository that allows security automation content to be discovered, syndicated, and exchanged. ROLIE is a profile of the Atom Syndication Format [9] and the Atom Publication Protocol [10].…”
Section: Ietf Roliementioning
confidence: 99%
“…Once completed, the applicability language will be piloted as part of the National Vulnerability Database (NVD) vulnerability feeds. 1 • ROLIE Extensions: ROLIE, defined by RFC8322 [8] provides a standardized method to easily identify and retrieve vulnerability records, SWID tags, configuration setting checklists, and other security content to support vulnerability and configuration setting assessment. ROLIE provides a content syndication approach that allows software creators, vulnerability reporters, and configuration setting checklist developers to establish federated repositories of the security content they produce.…”
Section: Scap V2 Development Planmentioning
confidence: 99%
“…Different from them, direct posting approach shares information without such entities. For instance, ROLIE publishes, shares, and exchanges security information as Web‐addressable resources by using Atom Publishing Protocol and Atom Syndication Format. Another such mechanism is XMPP‐based information publishing .…”
Section: Related Workmentioning
confidence: 99%