Re: Severity, in general [WAS: [IDMEF][Issue 10] Severity scale too narrow]

Ozakil Azim <[email protected]> Sun, 11 Jan 2004 17:47:05 -0500
Newsgroups gmane.ietf.idwg
Organization Ethercept, LLC
Message-ID <[email protected]>
Greg Shipley wrote:

>The severity topic is a can of worms, but I believe the adoption of "SIM"
>solutions (Security Information Management) in operational environments is
>a testament to the need for more flexible classification models.  Many of
>today's commercial SIM solutions will take in data from a security device
>(firewall, NIDS, etc.) and attach a weight to it based on other data
>points (asset rankings, vulnerability informations, etc.).
>
>  
>
Having worked on a SIM product in an earlier life, I tend to agree with 
Greg on this. Aggregating events and aggregating the impact of events 
was a problem we tried to solve by using a weighted system for risk 
assessment that took into consideration asset values, exposures, and 
perceived threats amongst other variables. An event reported by a 
'standalone' IDS was reevaluated in the context of the security of the 
whole enterprise.

 As per my reading of the draft, the 'severity' is an attribute of the 
'Impact' class that is meant to deliver the evaluated impact of the 
event as seen by the analyzer.  Even if this evaluation was used in a 
purely subjective manner, three grades of severity are too narrow. Given 
that the 'impact', as assessed by the 'analyzer',  may be further 
reassessed by higher order 'analyzers', we need to use some scale that 
can useful for further evaluation/aggregation. The question is whether 
one universal scale would suffice.

Analyzers assessing alerts from other analyzers need to take at least 
the following two aspects into consideration:
1) What is the trust relationship with the 'other' analyzer? Do I know 
this analyzer? What is my history with this analyzer? What is the role 
of this analyzer in the security posture of the enterprise? What is its 
rank in the security organization?  (my analogy drives from the P.o.V of 
a general gathering intelligence from a field agent :)
2) How severe does the analyzer think the event is? What is 'its' rating 
system? What are its grades?

Aspect 1) 'trust' between analyzers, I guess is out of scope of IDMEF. 
and aspect 2) seems to be what we are discussing.

My opinion is that the analyzer generating the alert knows best. If an 
analyzer decides based on its detection/analysis algorithms to have only 
three grades, that's okay.
If the analyzers decides to grade from 0-10,000 or 0.00 - 1.00, that's 
fine too. It would be great if the analyzer could specify the range of 
its 'severity' values on request
(or with each message - I may be wrong, but I don't seem to recall a 
query mechanism in the IDMEF draft). That way, each analyzer uses what 
it is most comfortable with, and leaves the 'normalizing' to the higher 
order 'analyzer'.

>That way, at least the decision of severity could be determined by
>endusers, implementors, data aggregation mechanisms, etc., and not be as
>limited.
>
>  
>
I agree that this decision needs to be re-determinable at all the way up 
the chain till the 'human'(A.I?) operator.

-azim
smime.p7s (application/x-pkcs7-signature, 4.6 KB) - not displayed