@@ -568,164 +568,254 @@ Indirect users of network interfaces include:
* People with little to no computer administration skills
* People with advanced computer administration skills
## 4.7 Use cases
The following use cases are provided to assist manufacturers in selecting risk factors and security levels. This is not intended to be an exhaustive or complete list of all possible use cases.
The examples given in each use case are for a finished product that includes the network interface. They are examples of a products which at least one of the core functionalities is to operate as a network interface.
* Professionally administered but likely under-resourced
### 4.7.2 Wireless network interface use cases
* UC-WL-1 Wireless professional device in isolated internal infrastructure
* E.g. Data centre for internal job processing, smart meter in an isolated private network
* Behind a firewall/gateway, no direct route to internet
* Users are administrators and approved (predefined, fixed) applications
* Interface implements radio control and encryption
* Professional administration
* UC-WL-2 Wireless stationary home IoT device
* E.g. IoT lightbulb, smart oven, stationary personal computer
* Behind home gateway firewall, network accessible by physically nearby attackers
* Host access limited to people within the home
* Interface implements radio control and encryption
* Non-professional administration
* UC-WL-3 Wireless professional edge device or internet infrastructure
* E.g. firewalls, VPN servers, switches in IXPs and ISPs, smart meter gateways and data concentrators in a smart metering system
* Exposed to entire internet on the public network side
* Users are administrators and approved applications
* Interface implements radio control and encryption
* Professional administration
* UC-WL-4 Wireless mobile enterprise worker device
* E.g. company laptop, phone, tablet
* Exposed to entire internet via any access point
* Users are company employees
* Interface implements radio control and encryption
* Professional administration
* UC-WL-5 Wireless stationary home computer
* E.g. stationary personal computer
* Behind home gateway firewall, network accessible by physically nearby attackers
* Host access limited to people within the home
* Interface implements radio control and encryption
* Non-professional administration
* UC-WL-6 Wireless mobile personal device
* E.g. laptop, phone, tablet, watch
* Exposed to entire internet, physically nearby attackers
* Users limited to owner and a few people they trust
* Interface implements radio control and encryption
* Non-professional administration
* UC-WL-7 Wireless stationary device for public use
* E.g. public library computer, vending machine
* Behind some firewall, network accessible by physically nearby attackers
* Can be used by literally anybody
* Interface implements radio control and encryption
* Professional administration but likely under-resourced
### 4.7.3 Virtual network interface use cases
* UC-VI-1 Virtual network interface for internal use on private or professional device
* E.g. loopback, containers, tunnel to local application
* Packets only from other applications/users on host
* Users limited to owner and who they trust
* Very simple device driver
* Professional administration
* UC-VI-2 Virtual network interface for external use on private device
* Virtio on hypervisors, VPN interfaces, tunnel interfaces
* Exposed to entire internet
* Users limited to owner and who they trust
* Highly complex packet filtering, processing, encryption, etc.
* Non-professional administration
* UC-VI-3 Virtual network interface for external use on enterprise device
* Virtio on hypervisors, VPN interfaces, tunnel interfaces
* Exposed to entire internet
* Users are company employees
* Highly complex packet filtering, processing, encryption, etc.
* Professional administration
* UC-VI-4 Virtual network interface for external use on public server
* Virtio on hypervisors, VPN interfaces, tunnel interfaces
* Exposed to entire internet
* Users are untrusted
* Highly complex packet filtering, processing, encryption, etc.
* Professional administration
## 4.6 Use Cases
<mark>Editor's Note: The use cases shall be defined as a combination of the product context elements described in clauses 4.1 to 4.5, clearly indicating:<br>
- Title the title of the use case, following a consistent naming/ID scheme (e.g., UC-3 Internet Connection)<br>
- Goal the goal of the use case (e.g., connect to the Internet)<br>
- Description via subclauses or bullet points which elements from each apply (i.e., product type: ..., function: ..., users: ..., architecture: ..., operational environment: ...)
</mark>
<mark>Editor’s Note: The standard may only be applied to those use cases listed in the standard. To ensure borad applicability, use cases should strive to covr all use cases known to the stnadardisers, with a view to aiming for full reflection of market realities. This can be achieved by staying at a level of abstraction granular enough to serve as basis for security analysis.</mark>
<mark>Editor’s Note: Use cases may include the case of critical infrastructure but shall refrain from an explicit link to the NIS 2 Directive.</mark>
### 4.6.1 Wired network interface use cases
#### 4.6.1.1 UC-WD-1 Wired stationary home IoT device
* Goal: Connect a home appliance to a home network for local control and monitoring
* Description:
* Examples: Network interfaces in thermostat, fridge
* Product type: Wired network interface
* Function: Connect host system to local private network, simple data transfer
* Complexity: Low
* User administration skill: Low
* Operational environment: Low sensitivity device connected to filtered private network in private home
#### 4.6.1.2 UC-WD-2 Wired professional device in isolated internal infrastructure
* Goal: Connect professional device to an isolated network
* Description:
* Examples: Network interfaces in data centre for internal job processing, smart meter in an isolated private network
* Product type: Wired network interface
* Function: Connect host system to a isolated network, moderately complex data transfer
* Complexity: Medium
* User administration skill: High
* Operational environment: Moderate sensitivity device in location accessible by authorized users only
#### 4.6.1.3 UC-WD-3 Wired professional internal infrastructure device
* Goal: Connect professional device to a filtered private network
* Description:
* Examples: Network interfaces in switches behind edge firewall devices
* Product type: Wired network interface
* Function: Connect host system to a filtered private network
* Complexity: Medium
* User administration skill: High
* Operational environment: Moderate sensitivity device connected in location accessible by authorized users only
#### 4.6.1.4 UC-WD-4 Wired professional edge device or internet infrastructure
* Goal: Connect professional device to public internet
* Description:
* Examples: Network interfaces in firewalls, VPN servers, switches in IXPs and ISPs, smart meter gateways and data concentrators in a smart metering system
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
#### 4.6.1.5 UC-WD-5 Wired stationary home gateway
* Goal: Connect home network to public network
* Description:
* Examples: Network interfaces in ISP-manage access point
* Product type: Wired interface
* Function: Connect and filter data from a public network to a private home network
* Complexity: Medium
* User administration skill: High (remotely managed by ISP staff)
* Operational environment: Low sensitivity devices connected to public network in private home
#### 4.6.1.6 UC-WD-6 Wired professional worker device on internal network
* Goal: Connect stationary professional device to filtered private network and public network
* Description:
* Examples: Network interfaces in stationary personal computer, registration terminal, cash register
* Product type: Wired network interface
* Function: Connect host system to a filtered private network
* Complexity: Medium
* User administration skill: High
* Operational environment: Medium sensitivity device connected to filtered private network and public network in public area
#### 4.6.1.7 UC-WD-7 Wired stationary home device
* Goal: Connect home device to a public network
* Description:
* Examples: Network interfaces in stationary personal computer, IoT hub, thermostat, TV
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
#### 4.6.1.8 UC-WD-8 Wired mobile device
* Goal: Connect mobile general purpose computing device to public network temporarily via wired connection
* Description:
* Examples: Network interfaces in laptop
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
#### 4.6.1.9 UC-WD-9 Wired stationary public server
* Goal: Connect server with multiple untrusted users to a public network
* Description:
* Examples: Network interfaces in shared webhosting
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: High
* Operational environment: Medium sensitivity device connected to public network via firewall in access-controlled area
#### 4.6.1.10 UC-WD-10 Wired stationary device for public use
* Goal: Connect public use device to public network via firewall
* Description:
* Examples: Network interfaces in public library computer, vending machine
* Product type: Wired network interface
* Function: Connect host system to a public network
* Complexity: Medium
* User administration skill: High
* Operational environment: Low sensitivity device connected to public network via firewall in public area
### 4.6.2 Wireless network interface use cases
#### 4.6.2.1 UC-WL-1 Wireless professional device in isolated internal infrastructure
* Goal: Connect professional device to isolated network
* Description:
* Examples: Network interfaces in data centre for internal job processing, smart meter in an isolated private network
* Product type: Wireless network interface
* Function: Connect host system to a isolated network
* Complexity: High
* User administration skill: High
* Operational environment: Medium sensitivity device connected to isolated network in access-controlled area
#### 4.6.2.2 UC-WL-2 Wireless stationary home IoT device
* Goal: Connect stationary home device to public internet via firewall
* Description:
* Examples: Network interfaces in lightbulb, smart oven, stationary personal computer
* Product type: Wireless network interface
* Function: Connect host system to a public network via firewall
* Complexity: High
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
#### 4.6.2.3 UC-WL-3 Wireless professional edge device or internet infrastructure
* Goal: Connect professional device to public internet
* Description:
* Examples: Network interfaces in firewalls, VPN servers, switches in IXPs and ISPs, smart meter gateways and data concentrators in a smart metering system
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Complexity: High
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
#### 4.6.2.4 UC-WL-4 Wireless mobile enterprise worker device
* Goal: Connect mobile general purpose computing device to public internet
* Description:
* Examples: Network interfaces in company laptop, phone, tablet
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Complexity: High
* User administration skill: High
* Operational environment: Medium sensitivity device connected to public network via firewall in public area
#### 4.6.2.5 UC-WL-5 Wireless stationary home device
* Goal: Connect home device to a public network
* Description:
* Examples: Network interfaces in stationary personal computer, IoT hub, thermostat, TV
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Complexity: High
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in private home
#### 4.6.2.6 UC-WL-6 Wireless mobile personal device
* Goal: Connect mobile general purpose computing device to public network
* Description:
* Examples: Network interfaces in laptop, phone, tablet, watch
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Complexity: High
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network via firewall in public area
#### 4.6.2.7 UC-WL-7 Wireless stationary device for public use
* Goal: Connect public use device to public network via firewall
* Description:
* Examples: Network interfaces in public library computer, vending machine
* Product type: Wireless network interface
* Function: Connect host system to a public network
* Complexity: High
* User administration skill: High
* Operational environment: Low sensitivity device connected to public network via firewall in public area
### 4.6.3 Virtual network interface use cases
#### 4.6.3.1 UC-VI-1 Virtual network interface for internal use on private or professional device
* Goal: Connect software within a host system
* Description:
* Examples: Network interfaces in loopback, containers, tunnel to local application
* Product type: Virtual network interface
* Function: Connect software within a single host
* Complexity: Low
* User administration skill: High
* Operational environment: Medium sensitivity software connected to isolated network within single host
#### 4.6.3.2 UC-VI-2 Virtual network interface for external use on private device
* Goal: Connect software to public networks indirectly
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect software to a public network
* Complexity: High
* User administration skill: Low
* Operational environment: Medium sensitivity device connected to public network in access-controlled area
#### 4.6.3.3 UC-VI-3 Virtual network interface for external use on enterprise device
* Goal: Connect software to public networks indirectly
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect software to a public network
* Complexity: High
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area
#### 4.6.3.4 UC-VI-4 Virtual network interface for external use on public server
* Goal: Connect software to public networks indirectly
* Description:
* Examples: Network interfaces for virtio on hypervisors, VPN interfaces, tunnel interfaces
* Product type: Virtual network interface
* Function: Connect arbitrary user software to a public network
* Complexity: High
* User administration skill: High
* Operational environment: High sensitivity device connected to public network in access-controlled area