Skip to content

Improve segmentation egress boundary evidence#1966

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/segmentation-egress-boundary-fixtures-1685
Open

Improve segmentation egress boundary evidence#1966
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/segmentation-egress-boundary-fixtures-1685

Conversation

@DENGXUELIN
Copy link
Copy Markdown

Closes #1685.

Summary

  • add an egress boundary and internet exit evidence gate to segmentation
  • require approved destination, enforcement point, DNS path, route/bypass, logging, and exception lifecycle evidence
  • add vulnerable and benign fixtures for broad NAT/port-only egress versus constrained egress boundaries

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • added-line ASCII check
  • content marker check for SEG-EGRESS-* findings and fixtures
  • git merge-tree --write-tree origin/main HEAD

Bounty

Requested tier: Improver Moderate, USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] segmentation: add egress boundary and internet exit evidence gates

1 participant