Threat intelligence

A continuously refreshed threat feed with input controls

DCSF treats external indicators as untrusted input: records are normalised, validated, deduplicated and aged before they can affect firewall policy.

DCSF

From indicator to enforceable policy

The feed pipeline favours provenance and predictable failure over raw list size.

01

Collect

Receive indicators from curated operational and research sources.

02

Validate

Confirm syntax, address scope, provenance and transport integrity.

03

Normalise

Canonicalise records and eliminate duplicate or conflicting entries.

04

Age

Expire indicators whose confidence or operational relevance has decayed.

05

Publish

Deliver versioned data through a controlled, failure-aware channel.

DCSF

Feed quality policy

The objective is useful protection with controlled false-positive risk.

Provenance

An indicator without an accountable source does not gain automatic trust.

Scope

Private, documentation and shared-infrastructure addresses require separate handling.

Ageing

Every entry has a lifecycle so historical data does not become a permanent block.

Source failure

A failed fetch cannot erase working policy or activate a partial file.

DH20.01 includes the maintained DataHouse Threat Feed source configuration. Data is validated before activation, and a failed download preserves the last known-good set.