Re: [IDMEF][Issue 8] Classification and ident

Krzysztof Zaraska <[email protected]> Mon, 12 Jan 2004 16:34:20 +0100 (CET)
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
On Sun, 11 Jan 2004, David A. Curry wrote:

> 
> >>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote:
> 
>   Herve> From Krzysztof Zaraska:  Also, we would propose introducing the "id"
>   Herve> field here, containing a unique identifier for the vulnerability in
>   Herve> given database, as we can see that "name" field is being rather used
>   Herve> as a description, and, as such, doesn't have to be unique. Having the
>   Herve> "id" field, the construction of the relevant URL is trivial (some
>   Herve> combination of database's base URL and the identifier).
> 
> I would prefer not to make the assumption that a URL could be generated from
> an ID.  By doing so, you're assuming that vulnerability databases and their
> URLs are built in a certain way, which is not an assumption that should be
> built into IDMEF.  Because as soon as you do it, someone's gonna break it.

Agreed. 

To clarify, the core of my argument is: neither classification.name nor
classification.url can be relied on to specify the vulnerability
accurately, hence the proposal of the "id" field. 

// Krzysztof Zaraska * kzaraska (at) student.uci.agh.edu.pl
// http://mops.uci.agh.edu.pl/~kzaraska/ * http://www.prelude-ids.org/
// A dream will always triumph over reality, once it is given the chance.
//		-- Stanislaw Lem