Re: [IDMEF][Issue 10] Severity scale too narrow

"David A. Curry" <[email protected]> Sun, 11 Jan 2004 21:06:13 -0500
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
>>>>> On Fri, 9 Jan 2004, Herve Debar, identified as "Herve" below, wrote:

  Herve> From Krzysztof Zaraska: severity scale (3 grades only) is too narrow;
  Herve> for example, there is an idea floating around of expressing the danger
  Herve> associated with the attack as exp(severity*vulnerabity_level), but you
  Herve> can't go far this way with 3 level severity scale only.

I am way skeptical of any scheme that purports to assign numerical values to
this type of data and claim that they are "accurate" in any meaningful way.

As I recall, the group was similarly skeptical when the idea was proposed in
the past (and it was proposed more than once).

  Herve> Hervé: we use 5 internally. It seems to be standard practice within
  Herve> the telco industry:  1) = critical 2) = warning 3) = minor 4) = normal
  Herve> 5) = unclassified/unclassifiable This wouldn't solve your graduation
  Herve> issue, but it actually is enough for an operator. We also use another
  Herve> scale which has 3 levels,(solved within 1/2 hour), (solved within 1/2
  Herve> day), (solved within 1 day), but that's maybe too operations-oriented.

This seems reasonable to me.  It's fairly standard in other areas as well,
e.g. Microsoft alerts (I think), FS/ISAC alerts, and others.

Although we could argue for hours about whether the numbers should be in
ascending or descending order (proposal: Herve's choice :-).

--Dave