Re: [IDMEF][Issue 5] duplicate information related to protocol information.

"David A. Curry" <[email protected]> Sun, 11 Jan 2004 20:48:40 -0500
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
>>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote:

  Herve> I somehow think that the protocol should be something like:

  Herve> <Protocol ip_version=[number] iana_number=[number] iana_name=[free
  Herve> text] >some text</Protocol>

  Herve> That way we would have any IP protocol represented.

This seems reasonable to me... it's at least quite a bit better than "tcp"
and "udp", and we'll at least need the flexibility of IPv4 -vs- IPv6
anyway...

  Herve> From Krzysztof Zaraska -> The problem is that we are usually dealing
  Herve> with a protocol stack.  Therefore, what about the layer 2 information
  Herve> for example? Ethernet addresses can go into into Source/Target, but
  Herve> what about, say, VPI/VCI fields in ATM, or any other connection
  Herve> identifier? [This is not an academic problem, as some people are
  Herve> trying to combine Prelude with logging all traffic at the session
  Herve> level for later inspection and would appreciate some form of
  Herve> connection identifier within the alert.]

I think Layer 2 is outside the scope of what IDMEF was originally thinking
about.  That doesn't mean it couldn't be added (although I'm loathe to do
so at this late date), or that Prelude (I don't know what that is, but I
assume it's an IDS project of some sort) couldn't define some type of an
extension for it.

--Dave