Re: [IDMEF][Issue 5] duplicate information related to protocol information.
"David A. Curry" <[email protected]> Sun, 11 Jan 2004 20:48:40 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote: Herve> I somehow think that the protocol should be something like: Herve> <Protocol ip_version=[number] iana_number=[number] iana_name=[free Herve> text] >some text</Protocol> Herve> That way we would have any IP protocol represented. This seems reasonable to me... it's at least quite a bit better than "tcp" and "udp", and we'll at least need the flexibility of IPv4 -vs- IPv6 anyway... Herve> From Krzysztof Zaraska -> The problem is that we are usually dealing Herve> with a protocol stack. Therefore, what about the layer 2 information Herve> for example? Ethernet addresses can go into into Source/Target, but Herve> what about, say, VPI/VCI fields in ATM, or any other connection Herve> identifier? [This is not an academic problem, as some people are Herve> trying to combine Prelude with logging all traffic at the session Herve> level for later inspection and would appreciate some form of Herve> connection identifier within the alert.] I think Layer 2 is outside the scope of what IDMEF was originally thinking about. That doesn't mean it couldn't be added (although I'm loathe to do so at this late date), or that Prelude (I don't know what that is, but I assume it's an IDS project of some sort) couldn't define some type of an extension for it. --Dave