Re: New rules for su root attempts
"Sebastien Tricaud" <[email protected]> Fri, 25 Jul 2008 17:19:27 +0200
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
> > Classification.text doesn't *need* to be the taxonomy field, does it? According to the IDMEF rfc: classification.text = A vendor-provided string identifying the Alert message. So, ok, as I cannot tell you this must be a taxonomy field, you cannot tell me the way around as well. We are stuck. The only difference is that we already use it in a way which is not taxonomy. One of its problem is that now, we have classification.text that look like this: "User authentication failed", which runs in conflict against other fields in idmef. assessment.impact.type is already set to "user" and "failed" is already in assessment.impact.completion > >> And the taxonomy must remain vague. It is a primary classification. > Details come afterwards, digging deeper in the IDMEF message. > > I don't agree. If it remains as vague as the snort classtype field, > it's useless. Might as well not even do it. Right. Vague means our own normalized classification: the type of attack/vulnerability. > > Again: *why* does classification.text have to be the taxonomy field? Why not ? However, as I answered on top of this email, we already have something. Adding the Taxonomy extension is what we should do if we decide to keep classification.text is its current state. Do you folks think we should avoid doing it into AdditionnalData ? _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel