Re: [IDMEF][Issue 8] Classification and ident
Krzysztof Zaraska <[email protected]> Mon, 12 Jan 2004 16:34:20 +0100 (CET)
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 11 Jan 2004, David A. Curry wrote: > > >>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote: > > Herve> From Krzysztof Zaraska: Also, we would propose introducing the "id" > Herve> field here, containing a unique identifier for the vulnerability in > Herve> given database, as we can see that "name" field is being rather used > Herve> as a description, and, as such, doesn't have to be unique. Having the > Herve> "id" field, the construction of the relevant URL is trivial (some > Herve> combination of database's base URL and the identifier). > > I would prefer not to make the assumption that a URL could be generated from > an ID. By doing so, you're assuming that vulnerability databases and their > URLs are built in a certain way, which is not an assumption that should be > built into IDMEF. Because as soon as you do it, someone's gonna break it. Agreed. To clarify, the core of my argument is: neither classification.name nor classification.url can be relied on to specify the vulnerability accurately, hence the proposal of the "id" field. // Krzysztof Zaraska * kzaraska (at) student.uci.agh.edu.pl // http://mops.uci.agh.edu.pl/~kzaraska/ * http://www.prelude-ids.org/ // A dream will always triumph over reality, once it is given the chance. // -- Stanislaw Lem