Re: New rules for su root attempts

"Sebastien Tricaud" <[email protected]> Fri, 25 Jul 2008 17:19:27 +0200
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
>
> Classification.text doesn't *need* to be the taxonomy field, does it?

According to the IDMEF rfc:

classification.text = A vendor-provided string identifying the Alert message.

So, ok, as I cannot tell you this must be a taxonomy field, you cannot
tell me the way around as well. We are stuck. The only difference is
that we already use it in a way which is not taxonomy.

One of its problem is that now, we have classification.text that look like this:
"User authentication failed", which runs in conflict against other
fields in idmef.
assessment.impact.type is already set to "user" and "failed" is
already in assessment.impact.completion

>
>> And the taxonomy must remain vague. It is a primary classification.
> Details come afterwards, digging deeper in the IDMEF message.
>
> I don't agree.  If it remains as vague as the snort classtype field,
> it's useless.  Might as well not even do it.

Right. Vague means our own normalized classification: the type of
attack/vulnerability.

>
> Again: *why* does classification.text have to be the taxonomy field?

Why not ?

However, as I answered on top of this email, we already have
something. Adding the Taxonomy extension is what we should do if we
decide to keep classification.text is its current state.

Do you folks think we should avoid doing it into AdditionnalData ?
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel