11.07.2015 Views

Email Protective Marking Standard for the Australian Government

Email Protective Marking Standard for the Australian Government

Email Protective Marking Standard for the Australian Government

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.6 Internet Message Header ExtensionIn this syntax <strong>the</strong> protective marking is carried as a custom Internet Message HeaderExtension “X-<strong>Protective</strong>-<strong>Marking</strong>”.• This approach is a more sophisticated technique that is an extension of <strong>the</strong> Subjectfield syntax. It is designed <strong>for</strong> construction and parsing by email agents (clients,gateways and servers) as <strong>the</strong>y have access to Internet message headers. In thisway a richer syntax can be used and email agents can per<strong>for</strong>m more complexhandling based on <strong>the</strong> protective marking.2.7 Syntax Precedence and QuantitiesBoth techniques MAY be used in a single email message so long as <strong>the</strong> protectivemarking is consistent across both.When a message contains both <strong>for</strong>ms of <strong>the</strong> protective marking, in<strong>for</strong>mation in <strong>the</strong> “X-<strong>Protective</strong>-<strong>Marking</strong>” SHALL take precedence over that in <strong>the</strong> Subject field.As per RFC2882, an Internet email message can have at most one Subject field.A message con<strong>for</strong>ming to this <strong>Standard</strong> MUST contain at most one “X-<strong>Protective</strong>-<strong>Marking</strong>” field.An email protective marking writer SHALL allow no more than one email protectivemarking in <strong>the</strong> subject line.2.7.1 Non-Compliant <strong>Marking</strong>sWhen a reader encounters an email with multiple protective markings in aSubject line, precedence SHALL be given to <strong>the</strong> first protective marking in <strong>the</strong>subject line. "First" means "leftmost" when reading left-to-right.2.8 Size of <strong>Protective</strong> <strong>Marking</strong>The protective marking, in ei<strong>the</strong>r Subject or Internet Message Header Extension <strong>for</strong>m,MUST NOT exceed a length of 8192 ASCII characters.• In principle, a protective marking may contain a number of DLMs/caveats. Thiscould provide a means <strong>for</strong> attackers to cause resource exhaustion on receivingagents. In practice, <strong>the</strong> length of protective marking will be bounded to somereasonable size which accommodates all current and future possible values. Thesize constraint given here should accommodate such values and thus minimiseavenues of attack.2.9 Syntax DefinitionsThe syntax <strong>for</strong> each protective marking is defined using two methods. A modifiedregular expression syntax using a <strong>for</strong>mat derived from script language regularexpressions and a <strong>for</strong>mal syntax using <strong>the</strong> Augmented Backus-Naur Form (ABNF)notation as used by RFC2822.If <strong>the</strong>re are any ambiguities arising from <strong>the</strong> two syntaxes <strong>the</strong>n <strong>the</strong> ABNF syntax SHALLbe definitive.10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!