Re: New rules for su root attempts
"G Ramon Gomez" <[email protected]> Fri, 25 Jul 2008 07:22:04 -0700
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <622FD37285F1584386F5F83D9D233C9C02CC28B2@SMF-ENTXM-001.sac.ragingwire.net> |
> Taxonomization == classification.text, maybe a better marketing synonym. > > Correlation engines need classification.text, which is as important as the kind of sensor we are dealing with. I don't understand this pair of statements. Classification.text doesn't *need* to be the taxonomy field, does it? > That is the way it is done today, that is want we want to fix because the current situation is really a mess. As of today, we suffer from the misunderstanding of all those alerts coming from all those sensors. And please, if you are too snort centric, forget about snort and try to see events as a whole. I don't even use Snort any more. However, I'm focused on the business aspect of the discussion; most users of Prelude are going to be using Snort. I think you'd be challenged to find a more widely-deployed piece of security software. > And the taxonomy must remain vague. It is a primary classification. Details come afterwards, digging deeper in the IDMEF message. I don't agree. If it remains as vague as the snort classtype field, it's useless. Might as well not even do it. >Please don't. Enough of additional_data garbage because if IDMEF insufficient to do a proper job. Classification.text is for what you call Taxonomy. Again: *why* does classification.text have to be the taxonomy field? _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel