Re: New rules for su root attempts

"G Ramon Gomez" <[email protected]> Fri, 25 Jul 2008 07:22:04 -0700
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <622FD37285F1584386F5F83D9D233C9C02CC28B2@SMF-ENTXM-001.sac.ragingwire.net>
> Taxonomization == classification.text, maybe a better marketing
synonym.
>
> Correlation engines need classification.text, which is as important as
the kind of sensor we are dealing with. 

I don't understand this pair of statements.  Classification.text doesn't
*need* to be the taxonomy field, does it?

> That is the way it is done today, that is want we want to fix because
the current situation is really a mess. As of today, we suffer from the
misunderstanding of all those alerts coming from all those sensors. And
please, if you are too snort centric, forget about snort and try to see
events as a whole.

I don't even use Snort any more.  However, I'm focused on the business
aspect of the discussion; most users of Prelude are going to be using
Snort.  I think you'd be challenged to find a more widely-deployed piece
of security software.

> And the taxonomy must remain vague. It is a primary classification.
Details come afterwards, digging deeper in the IDMEF message.

I don't agree.  If it remains as vague as the snort classtype field,
it's useless.  Might as well not even do it.

>Please don't. Enough of additional_data garbage because if IDMEF
insufficient to do a proper job. Classification.text is for what you
call Taxonomy.

Again: *why* does classification.text have to be the taxonomy field?
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel