header information
163551·updated Aug 30, 2026The structured metadata carried in the leading section of a network packet or message, as distinguished from the payload or body, comprising fields such as source and destination addresses, port numbers, and protocol type. It includes attributes such as "source and destination IP address(s), source and destination port(s), and protocol type(s)" — the routing and control fields that describe where a transmission comes from, where it is going, and how it is to be handled. In security enforcement, boundary protection devices use it to "provide a packet-filtering capability based on header information" as a first-pass control mechanism, distinct from deeper content-based inspection of the payload. It represents a shallower inspection surface than full stateful or content analysis, which is why Access Control Lists that "filter based on header information" are considered less capable than stateful inspection.
Source
, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content (e.g., implementing key word searches or using document characteristics). Organizations also consider the trustworthiness of filtering and inspection mechanisms (i.e., hardware, firmware, and software components) that are critical tothe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- Filtering network data transfers
- SL5 Standard for AI Security
- Stateful Inspection - an overview | ScienceDirect Topics
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
The structured routing and control metadata carried in the prefix section of a network packet or protocol message — distinct from the payload — comprising fields such as source and destination addresses, ports, and protocol type. The packet header contains information about the source IP address, destination IP address, protocol and port, making it the portion of a transmission unit that describes *how* traffic moves rather than *what* it carries. Packet filters compare this information — source and destination IP addresses, ports, and protocol types — with filtering rules that define a network usage or security policy, which is the canonical enforcement use: boundary protection devices employ rule sets or configuration settings that restrict system services or provide a packet-filtering capability based on header information, as opposed to deeper content inspection of the payload. The phrase is compositional — "header" and "information" each carry their ordinary technical meanings — but the combination functions as a stable shorthand in network security and information flow control contexts for the totality of routing/control metadata available to a boundary enforcement device wit
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- header informations
- possessive
- header information's
- pluralpossessive
- header informations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The structured metadata carried in the leading section of a network packet or message, as distinguished from the payload or body, comprising fields such as source and destination addresses, port numbers, and protocol type. It includes attributes such as "source and destination IP address(s), source and destination port(s), and protocol type(s)" — the routing and control fields that describe where a transmission comes from, where it is going, and how it is to be handled. In security enforcement, boundary protection devices use it to "provide a packet-filtering capability based on header information" as a first-pass control mechanism, distinct from deeper content-based inspection of the payload. It represents a shallower inspection surface than full stateful or content analysis, which is why Access Control Lists that "filter based on header information" are considered less capable than stateful inspection.DR-088 backfill from the noun definition column