Re: New rules for su root attempts

"Sebastien Tricaud" <[email protected]> Fri, 25 Jul 2008 17:30:04 +0200
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
On Fri, Jul 25, 2008 at 4:57 PM, Yoann Vandoorselaere
<[email protected]> wrote:

>
> classification.text is a text field: an enumeration member would be
> better suited to force a given sensor to rely on the taxonomy
> dictionary.
>
> Although we can keep using classification.text, and making sure the
> input value is "acceptable".

Let's do one or the other but not both.

I think we can all agree to have an enumeration member with attack
taxonomy, so now how to do that ? While I am against putting
everything in AdditionnalData, maybe it is the best to remain
compatible with the other vendors.

>
> Finally, the question is more whether we will be able to fix <insert
> sensor name> in a transparent way when <our own|CEE|any taxonomy
> dictionary> come out.

We should make our own, and then being able to work with CEE/IDMEF/any
other standard.

>
> Anyway, the first step will probably be that a first draft of CEE
> taxonomy come out so that we can see if we deem it viable for the
> Prelude system.

I would avoid a wait and see attitude because we need something right
now. Plus it is way easier for us to adapt, make extensions to our own
system than always waiting. However standards are important, and we
should really make sure our model can be exported in
IDMEF/CEE/whatever.

>
> It really depend on the taxonomy draft we decide to adopt in the future.
> There might be multiples fields required.

What do you think of the model I've put previously in this thread, the
one Steeve commented etc.. ? To me this is a starting point, I can
write a wiki page with this and we can start having our own thing this
way.

>
>
>> Since IDMEF is dead, and since Prelude is very active, we will add our
>> custom fields soon or latter.
>
> IDMEF is used by all Prelude sensors, including others IDS from others
> companies. I would not say it is a dead standard, even through there is
> no active work group improving it at the moment.

It is at least a standard, used but soon to be dead if they don't fix
all those details we are complaining about. If they don't move ahead,
that will be replaced for sure in the years to come.

>
> Keep in mind IDMEF has required an enormous amount of work, that
> mobilized a lot of persons, and even thought it's not perfect, the
> security/SIM landscape owe a lot to it.

I've seen it, I was already in the landscape. I totally agree we you on this.
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel