Re: New rules for su root attempts
"Sebastien Tricaud" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Jul 23, 2008 at 4:46 PM, Yoann Vandoorselaere <[email protected]> wrote: > > Currently, a lot of alert generated use word to indicate > successful/failed completion within classification.text. > And even "User authentication" is too much. Since we have the target user in the IDMEF path. I'd do a generic Authentication classification.text instead. Bellow the attack classification Pierre and I designed: Authentication Local user System user Admin user Other Probe Protocol Scan Sniff Users Other Corruption File Application Other Availability (Denial of Service) Resource consumption User account locking Application crash Other The other is a garbage, but unlike IDMEF and its AdditionalData, it is not a global garbage. It is a garbage per classification. In order to get a picture of the classification work, one can see this: http://www.secviz.org/content/nessus-vulnerability-scanner-pigized The "alert.classification.text" should not be like that, I'd rather see more points converging, showing that events are properly classified. (And yes, this is likely to be IDMEF centric work here, but the IDWG is dissolved and people believe they've done the work and it is now over, which is.. of course not the case) Cheers, Sebastien. _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel