Re: [Prelude Hybrid IDS] #244: New LML-Ruleset for Honeytrap - please review
"Prelude Hybrid IDS" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#244: New LML-Ruleset for Honeytrap - please review
-------------------------+--------------------------------------------------
Reporter: bjou | Owner: yoann
Type: defect | Status: new
Priority: normal | Milestone:
Component: prelude-lml | Version: 0.9
Severity: trivial | Resolution:
Keywords: |
-------------------------+--------------------------------------------------
Comment (by yoann):
Great contribution! Some comments from #245 and #246 apply, with
additional:
* ''Reconnaissance Probe at port $1'' -> No variable element should be
assigned within the classification (to easily sort / search / store
elements). I'd suggest using ''Reconnaissance Probe''.
* ''A connection to honeytrap has been established. No bytes have been
received, though.'' wouldn't the following wording be more clear: ''A
connection to honeytrap has been established, but no data was received.''
* ''additional_data(0).meaning=Size'' -> ''Attack string size'' would be
self describing.
* In rule id ''40002'', shouldn't the filename be set within IDMEF
Target.file?
Hope this help!
--
Ticket URL: <https://trac.prelude-ids.org/ticket/244#comment:2>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel