[Prelude Hybrid IDS] #163: Add snort classification.reference to Snort.org site

Prelude Hybrid IDS <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#163: Add snort classification.reference to Snort.org site
---------------------+------------------------------------------------------
 Reporter:  grgomez  |       Owner:  yoann
     Type:  defect   |      Status:  new  
 Priority:  normal   |   Milestone:       
Component:  snort    |     Version:  0.9  
 Severity:  normal   |    Keywords:       
---------------------+------------------------------------------------------
 Snort Prelude output should provide an implicit classification.reference
 entry for SIDs less than 100000 (higher than this are likely to be
 Bleedingsnort or custom rulesets).
 For an example rule 1742, this URL would look like this:

 http://www.snort.org/pub-bin/sigs.cgi?sid=1742

 Form an example resulting IDMEF classification.reference like this:

  classification.reference(0).origin=vendor-specific; \
  classification.reference(0).meaning=Snort SID; \
  classification.reference(0).name=1742; \
  classification.reference(0).url=http://www.snort.org/pub-
 bin/sigs.cgi?sid=1742; \

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/163>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite

_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.