IDMEF Implementations (fwd)
"David A. Curry" <[email protected]> Tue, 13 Jan 2004 10:31:35 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
Detmar, I'm copying your message to the IDWG mailing list; maybe there's some folks there with an interest who can help you. --Dave ------- Forwarded Message From: Detmar Liesen <[email protected]> To: [email protected] Date: Tue, 13 Jan 2004 08:08:56 +0100 Subject: IDMEF Implementations Hi David, we proudly present.... The threatman-project (www.sourceforge.net/projects/threatman) has released first alpha code for the idmef/idxp-device-proxy, one basic part of the threat-management framework that we're developing. Until now we can't do much more than sending back and forth idmef-messages over the beep tunnel, but it's a first start. Sandro Poppi, who has also taken over maintenance of the snort-idmef-plugin (www.sourceforge.net/projects/snort-idmef), has done the most programming. Next, we'll try to write first proof-of-concept code for correlating idmef-messages with asset/vuln. information. Do you have some good advise, how to handle this? What are the best methods for comparing xml-data from different xml-docs? What methods shall we use for storing data (xml-db with mysql or native xml). You know, I don't want to reinvent the wheel... ;) Of course it'd be great to plug into the acid database, so that correlation information can be displayed within acid. We will provide an acid-output plugin for sure. I think I am going to use perl for the correlation-engine as a start, because with perl it's much easier to write proof-of-concept code when you're not such an advanced programmer. We can backport the code to C/C++ later. I'd be very grateful for your ideas and comments. Thanks, --Detmar -- +++ GMX - die erste Adresse für Mail, Message, More +++ Neu: Preissenkung für MMS und FreeMMS! http://www.gmx.net ------- End of Forwarded Message