Collect
Receive indicators from curated operational and research sources.
DCSF treats external indicators as untrusted input: records are normalised, validated, deduplicated and aged before they can affect firewall policy.
The feed pipeline favours provenance and predictable failure over raw list size.
Receive indicators from curated operational and research sources.
Confirm syntax, address scope, provenance and transport integrity.
Canonicalise records and eliminate duplicate or conflicting entries.
Expire indicators whose confidence or operational relevance has decayed.
Deliver versioned data through a controlled, failure-aware channel.
The objective is useful protection with controlled false-positive risk.
An indicator without an accountable source does not gain automatic trust.
Private, documentation and shared-infrastructure addresses require separate handling.
Every entry has a lifecycle so historical data does not become a permanent block.
A failed fetch cannot erase working policy or activate a partial file.