Re: Severity, in general [WAS: [IDMEF][Issue 10] Severity scale too narrow]
Ozakil Azim <[email protected]> Sun, 11 Jan 2004 17:47:05 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | Ethercept, LLC |
| Message-ID | <[email protected]> |
Greg Shipley wrote: >The severity topic is a can of worms, but I believe the adoption of "SIM" >solutions (Security Information Management) in operational environments is >a testament to the need for more flexible classification models. Many of >today's commercial SIM solutions will take in data from a security device >(firewall, NIDS, etc.) and attach a weight to it based on other data >points (asset rankings, vulnerability informations, etc.). > > > Having worked on a SIM product in an earlier life, I tend to agree with Greg on this. Aggregating events and aggregating the impact of events was a problem we tried to solve by using a weighted system for risk assessment that took into consideration asset values, exposures, and perceived threats amongst other variables. An event reported by a 'standalone' IDS was reevaluated in the context of the security of the whole enterprise. As per my reading of the draft, the 'severity' is an attribute of the 'Impact' class that is meant to deliver the evaluated impact of the event as seen by the analyzer. Even if this evaluation was used in a purely subjective manner, three grades of severity are too narrow. Given that the 'impact', as assessed by the 'analyzer', may be further reassessed by higher order 'analyzers', we need to use some scale that can useful for further evaluation/aggregation. The question is whether one universal scale would suffice. Analyzers assessing alerts from other analyzers need to take at least the following two aspects into consideration: 1) What is the trust relationship with the 'other' analyzer? Do I know this analyzer? What is my history with this analyzer? What is the role of this analyzer in the security posture of the enterprise? What is its rank in the security organization? (my analogy drives from the P.o.V of a general gathering intelligence from a field agent :) 2) How severe does the analyzer think the event is? What is 'its' rating system? What are its grades? Aspect 1) 'trust' between analyzers, I guess is out of scope of IDMEF. and aspect 2) seems to be what we are discussing. My opinion is that the analyzer generating the alert knows best. If an analyzer decides based on its detection/analysis algorithms to have only three grades, that's okay. If the analyzers decides to grade from 0-10,000 or 0.00 - 1.00, that's fine too. It would be great if the analyzer could specify the range of its 'severity' values on request (or with each message - I may be wrong, but I don't seem to recall a query mechanism in the IDMEF draft). That way, each analyzer uses what it is most comfortable with, and leaves the 'normalizing' to the higher order 'analyzer'. >That way, at least the decision of severity could be determined by >endusers, implementors, data aggregation mechanisms, etc., and not be as >limited. > > > I agree that this decision needs to be re-determinable at all the way up the chain till the 'human'(A.I?) operator. -azim
smime.p7s
(application/x-pkcs7-signature, 4.6 KB) - not displayed