[Prelude Hybrid IDS] #213: LML rulesets should be updated to user IDMEF Action

"Prelude Hybrid IDS" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#213: LML rulesets should be updated to user IDMEF Action
-------------------------+--------------------------------------------------
 Reporter:  yoann        |       Owner:  gegomez
     Type:  defect       |      Status:  new    
 Priority:  normal       |   Milestone:         
Component:  prelude-lml  |     Version:  0.9    
 Severity:  normal       |    Keywords:         
-------------------------+--------------------------------------------------
 Current rulesets (except modsecurity) does not make use of the IDMEF
 Action class.

 {{{
 4.2.6.2.  The Action Class

    The Action class is used to describe any actions taken by the
    analyzer in response to the event.
    category

       The type of action taken.  The permitted values are shown below.
       The default value is "other".  (See also Section 10.)

    +------+-------------------+----------------------------------------+
    | Rank | Keyword           | Description                            |
    +------+-------------------+----------------------------------------+
    |    0 | block-installed   | A block of some sort was installed to  |
    |      |                   | prevent an attack from reaching its    |
    |      |                   | destination.  The block could be a     |
    |      |                   | port block, address block, etc., or    |
    |      |                   | disabling a user account.              |
    |      |                   |                                        |
    |    1 | notification-sent | A notification message of some sort    |
    |      |                   | was sent out-of-band (via pager,       |
    |      |                   | e-mail, etc.).  Does not include the   |
    |      |                   | transmission of this alert.            |
    |      |                   |                                        |
    |    2 | taken-offline     | A system, computer, or user was taken  |
    |      |                   | offline, as when the computer is shut  |
    |      |                   | down or a user is logged off.          |
    |      |                   |                                        |
    |    3 | other             | Anything not in one of the above       |
    |      |                   | categories.                            |
    +------+-------------------+----------------------------------------+

       The element itself may be empty, or may contain a textual
       description of the action, if the analyzer is able to provide
       additional details.
 }}}

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/213>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.