Re: [IDMEF][Issue 8] Classification and ident
"David A. Curry" <[email protected]> Sun, 11 Jan 2004 20:52:27 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote: Herve> From Krzysztof Zaraska: Also, we would propose introducing the "id" Herve> field here, containing a unique identifier for the vulnerability in Herve> given database, as we can see that "name" field is being rather used Herve> as a description, and, as such, doesn't have to be unique. Having the Herve> "id" field, the construction of the relevant URL is trivial (some Herve> combination of database's base URL and the identifier). I would prefer not to make the assumption that a URL could be generated from an ID. By doing so, you're assuming that vulnerability databases and their URLs are built in a certain way, which is not an assumption that should be built into IDMEF. Because as soon as you do it, someone's gonna break it. If the goal is that the analyzer, in the end, should have a URL to go to, then a URL is what should be sent. If the goal is to have an ID at the end (which may or may not be convertible to a URL), then an ID should be sent. But let's not have IDMEF dictating how one can be built from the other. --Dave