Re: [Prelude Hybrid IDS] #244: New LML-Ruleset for Honeytrap - please review

"Prelude Hybrid IDS" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#244: New LML-Ruleset for Honeytrap - please review
-------------------------+--------------------------------------------------
 Reporter:  bjou         |        Owner:  yoann
     Type:  defect       |       Status:  new  
 Priority:  normal       |    Milestone:       
Component:  prelude-lml  |      Version:  0.9  
 Severity:  trivial      |   Resolution:       
 Keywords:               |  
-------------------------+--------------------------------------------------
Comment (by yoann):

 Great contribution! Some comments from #245 and #246 apply, with
 additional:


  * ''Reconnaissance Probe at port $1'' -> No variable element should be
 assigned within the classification (to easily sort / search / store
 elements). I'd suggest using ''Reconnaissance Probe''.

  * ''A connection to honeytrap has been established. No bytes have been
 received, though.'' wouldn't the following wording be more clear: ''A
 connection to honeytrap has been established, but no data was received.''

  * ''additional_data(0).meaning=Size'' -> ''Attack string size'' would be
 self describing.

  * In rule id ''40002'', shouldn't the filename be set within IDMEF
 Target.file?

 Hope this help!

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/244#comment:2>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.