Re: New rules for su root attempts
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1216885645.6943.68.camel@arwen> |
Le mercredi 23 juillet 2008 à 17:25 +0200, Sebastien Tricaud a écrit : > On Wed, Jul 23, 2008 at 4:46 PM, Yoann Vandoorselaere > <[email protected]> wrote: > > > > Currently, a lot of alert generated use word to indicate > > successful/failed completion within classification.text. > > [...] > Bellow the attack classification Pierre and I designed: > Authentication > Local user > System user > Admin user > Other [...] > The "alert.classification.text" should not be like that, I'd rather > see more points converging, showing that events are properly > classified. > > > (And yes, this is likely to be IDMEF centric work here, but the IDWG > is dissolved and people believe they've done the work and it is now > over, which is.. of course not the case) You might want to have a look at the CEE (Common Event Expression): http://cee.mitre.org/ceelanguage.html#event The roadmap state that a first draft of the Common Event Taxonomy will be out in 2008. Regards, -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel