Re: New rules for su root attempts

"Sebastien Tricaud" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
On Wed, Jul 23, 2008 at 4:46 PM, Yoann Vandoorselaere
<[email protected]> wrote:
>
> Currently, a lot of alert generated use word to indicate
> successful/failed completion within classification.text.
>

And even "User authentication" is too much. Since we have the target
user in the IDMEF path.

I'd do a generic Authentication classification.text instead.

Bellow the attack classification Pierre and I designed:
    Authentication
         Local user
         System user
         Admin user
         Other
    Probe
         Protocol
         Scan
         Sniff
         Users
         Other
    Corruption
         File
         Application
         Other
    Availability (Denial of Service)
         Resource consumption
         User account locking
         Application crash
         Other

The other is a garbage, but unlike IDMEF and its AdditionalData, it is
not a global garbage. It is a garbage per classification.

In order to get a picture of the classification work, one can see
this: http://www.secviz.org/content/nessus-vulnerability-scanner-pigized

The "alert.classification.text" should not be like that, I'd rather
see more points converging, showing that events are properly
classified.


(And yes, this is likely to be IDMEF centric work here, but the IDWG
is dissolved and people believe they've done the work and it is now
over, which is.. of course not the case)


Cheers,
Sebastien.
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.