A Bird's-Eye View on Security Considerations in RFCs

2026-08-10Cryptography and Security

Cryptography and SecurityNetworking and Internet Architecture
AI summary

The authors studied the security sections that are required in Internet protocol documents called RFCs. They found that most RFCs talk about security, but they rarely include strict security rules. The connections between these security sections across RFCs are generally weak, except for a few that are frequently referenced. The topics in these sections tend to focus on specific security concerns for each protocol rather than broad issues like hacking or spying. This study provides new insights into how security is addressed in Internet standards over time.

RFCIETFInternet protocolssecurity considerationsnetwork securityprotocol-specific securitystandardizationreference network
Authors
Jukka Ruohonen, Qusai Ramadan
Abstract
Request for comments (RFCs) are Internet standards, memorandums, and related technical documents about core Internet protocols made via and released by the Internet Engineering Task Force (IETF). In the early 1990s each RFC was required to have a section for security considerations. The present work examines these sections. According to the empirical results, (1) over 90% of the RFCs sampled have discussed security explicitly in these sections, (2) although mandatory security requirements have only seldom-if ever-been imposed. Furthermore, (3) the RFC-to-RFC reference network specific to the security consideration sections is sparse, although a few RFCs and their security consideration sections are heavily referenced. In addition, (4) the volume of references peaked during a period from circa mid-1990s to mid-2010s. Regarding the topics discussed in the sections, (5) these do not represent general security issues, such as spoofing or eavesdropping; rather, the topics mostly reflect distinct security issues specific to distinct protocols. With the exceptions of network security in general, security specifications, and routing, (6) also the longitudinal evolution of the topics is protocol-specific. As the subject matter has not been previously examined, these empirical results fill a gap in the standardization literature.