[Prelude Hybrid IDS] #163: Add snort classification.reference to Snort.org site
Prelude Hybrid IDS <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#163: Add snort classification.reference to Snort.org site
---------------------+------------------------------------------------------
Reporter: grgomez | Owner: yoann
Type: defect | Status: new
Priority: normal | Milestone:
Component: snort | Version: 0.9
Severity: normal | Keywords:
---------------------+------------------------------------------------------
Snort Prelude output should provide an implicit classification.reference
entry for SIDs less than 100000 (higher than this are likely to be
Bleedingsnort or custom rulesets).
For an example rule 1742, this URL would look like this:
http://www.snort.org/pub-bin/sigs.cgi?sid=1742
Form an example resulting IDMEF classification.reference like this:
classification.reference(0).origin=vendor-specific; \
classification.reference(0).meaning=Snort SID; \
classification.reference(0).name=1742; \
classification.reference(0).url=http://www.snort.org/pub-
bin/sigs.cgi?sid=1742; \
--
Ticket URL: <https://trac.prelude-ids.org/ticket/163>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel