Re: [IDMEF][Issue 10] Severity scale too narrow
"David A. Curry" <[email protected]> Sun, 11 Jan 2004 21:06:13 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> On Fri, 9 Jan 2004, Herve Debar, identified as "Herve" below, wrote: Herve> From Krzysztof Zaraska: severity scale (3 grades only) is too narrow; Herve> for example, there is an idea floating around of expressing the danger Herve> associated with the attack as exp(severity*vulnerabity_level), but you Herve> can't go far this way with 3 level severity scale only. I am way skeptical of any scheme that purports to assign numerical values to this type of data and claim that they are "accurate" in any meaningful way. As I recall, the group was similarly skeptical when the idea was proposed in the past (and it was proposed more than once). Herve> Hervé: we use 5 internally. It seems to be standard practice within Herve> the telco industry: 1) = critical 2) = warning 3) = minor 4) = normal Herve> 5) = unclassified/unclassifiable This wouldn't solve your graduation Herve> issue, but it actually is enough for an operator. We also use another Herve> scale which has 3 levels,(solved within 1/2 hour), (solved within 1/2 Herve> day), (solved within 1 day), but that's maybe too operations-oriented. This seems reasonable to me. It's fairly standard in other areas as well, e.g. Microsoft alerts (I think), FS/ISAC alerts, and others. Although we could argue for hours about whether the numbers should be in ascending or descending order (proposal: Herve's choice :-). --Dave