header information
The structured metadata carried in the leading section of a network packet or message, as distinguished from the payload or body, comprising fields such as source and destination addresses, port numbers, and protocol type. It includes attributes such as "source and destination IP address(s), source and destination port(s), and protocol type(s)" — the routing and control fields that describe where a transmission comes from, where it is going, and how it is to be handled. In security enforcement, boundary protection devices use it to "provide a packet-filtering capability based on header information" as a first-pass control mechanism, distinct from deeper content-based inspection of the payload. It represents a shallower inspection surface than full stateful or content analysis, which is why Access Control Lists that "filter based on header information" are considered less capable than stateful inspection.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The structured metadata carried in the leading section of a network packet or message, as distinguished from the payload or body, comprising fields such as source and destination addresses, port numbers, and protocol type. It includes attributes such as "source and destination IP address(s), source and destination port(s), and protocol type(s)" — the routing and control fields that describe where a transmission comes from, where it is going, and how it is to be handled. In security enforcement, boundary protection devices use it to "provide a packet-filtering capability based on header information" as a first-pass control mechanism, distinct from deeper content-based inspection of the payload. It represents a shallower inspection surface than full stateful or content analysis, which is why Access Control Lists that "filter based on header information" are considered less capable than stateful inspection.DR-088 backfill from the noun definition column