Re: New rules for su root attempts
Yoann Vandoorselaere <[email protected]> Mon, 28 Jul 2008 11:19:08 +0200
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1217236748.6579.17.camel@arwen> |
Le vendredi 25 juillet 2008 à 17:30 +0200, Sebastien Tricaud a écrit : > On Fri, Jul 25, 2008 at 4:57 PM, Yoann Vandoorselaere > <[email protected]> wrote: > > > > > classification.text is a text field: an enumeration member would be > > better suited to force a given sensor to rely on the taxonomy > > dictionary. > > > > Although we can keep using classification.text, and making sure the > > input value is "acceptable". > > Let's do one or the other but not both. > > I think we can all agree to have an enumeration member with attack > taxonomy, so now how to do that ? While I am against putting > everything in AdditionnalData, maybe it is the best to remain > compatible with the other vendors. Waiting that a taxonomy standard come out, will allow us to plan for a correct implementation. > > Finally, the question is more whether we will be able to fix <insert > > sensor name> in a transparent way when <our own|CEE|any taxonomy > > dictionary> come out. > > We should make our own, and then being able to work with CEE/IDMEF/any > other standard. I think you are misunderstanding what CEE/CET (Common Event Taxonomy) is, have a look at http://cee.mitre.org/ceelanguage.html#event To my knowledge, this should be the first public, complete, and community based taxonomy dictionary available. > > Anyway, the first step will probably be that a first draft of CEE > > taxonomy come out so that we can see if we deem it viable for the > > Prelude system. > > I would avoid a wait and see attitude because we need something right > now. Plus it is way easier for us to adapt, make extensions to our own > system than always waiting. However standards are important, and we > should really make sure our model can be exported in > IDMEF/CEE/whatever. Doing what you suggest would probably involve breaking communication compatibility between Prelude modules. If that were to be done, I'd rather do it once. > > It really depend on the taxonomy draft we decide to adopt in the future. > > There might be multiples fields required. > > What do you think of the model I've put previously in this thread, the > one Steeve commented etc.. ? To me this is a starting point, I can > write a wiki page with this and we can start having our own thing this > way. This is a good starting point and should probably go to a wiki page, along with the current Snort classification taxonomy, as well as a pointer to the CET page. However, this is something that has only got the eyes from two person (I think only Pierre Chifflier and yourself worked on this), and thus, I'd expect a lot of other people review before being able to turn that into a full dictionary. -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel