secubox-deb/docs/specs
CyberMind-FR 948774f7fc docs(specs): integrate CM-WALL-EGRESS-2026-06 v0.1.0-draft + agent context
Spec stored under docs/specs/ for source of truth.

Module : WALL (paire complémentaire WALL↔MIND), compagnon de
CM-MESH-MPCIE-2026-06. Détection egress + corrélation menaces sur
Gondwana-Air.

Frontière R1/R2 intangible :
  R1 — métadonnées (flux, DNS, TLS-méta, IP-intel, NIDS) : licite
       sur accès ouvert, détection passive par défaut.
  R2 — contenu (TLS-break, DPI profonde, file-extract) : segments
       consentis/gérés UNIQUEMENT, opt-in journalisé.

Couches L0-L5 décrites avec outils ARM64 (Suricata 7.x, Zeek,
unbound+RPZ, goflow2/nfdump, feeds abuse.ch/ET/Spamhaus/MISP).

Contrainte ECH 2026 actée : SNI chiffré → poids sur L0 flux + L2
JA4 + L3 IP-intel + cadence, jamais sur SNI seul.

packages/secubox-egress/CLAUDE.md : agent context complet, DoD §1,
garde-fous §2 (R1/R2 intangible, OPAD, ECH-ready, secrets hors
TOML, LCEN), arborescence §3, TOML §4, API §5 (5 endpoints), NIDS
§6, .deb §7, ordre tâches §8, tests bench Maurienne §9.

Refus runtime câblé dans api.py : POST /wall/quarantine avec
regime=r2 + vlan=open_access_vlan → 403 (interception illicite).
Corrélation correlate.py exige multi_signal_threshold concordants
avant verdict quarantine (anti-faux-positif cloud-intel).
2026-06-02 11:13:44 +02:00
..
CM-MESH-MPCIE-2026-06.md docs(specs): integrate CM-MESH-MPCIE-2026-06 v0.2.1-draft 2026-06-02 11:06:40 +02:00
CM-WALL-EGRESS-2026-06.md docs(specs): integrate CM-WALL-EGRESS-2026-06 v0.1.0-draft + agent context 2026-06-02 11:13:44 +02:00