IDMEF Implementations (fwd)

"David A. Curry" <[email protected]> Tue, 13 Jan 2004 10:31:35 -0500
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
Detmar,

I'm copying your message to the IDWG mailing list; maybe there's some folks
there with an interest who can help you.

--Dave

------- Forwarded Message


  From:    Detmar Liesen <[email protected]>
  To:      [email protected]
  Date:    Tue, 13 Jan 2004 08:08:56 +0100
  Subject: IDMEF Implementations

  Hi David,
  we proudly present....
  
  The threatman-project (www.sourceforge.net/projects/threatman) has released
  first alpha code for the idmef/idxp-device-proxy, one basic part of the
  threat-management framework that we're developing.
  
  Until now we can't do much more than sending back and forth idmef-messages
  over the beep tunnel, but it's a first start.
  
  Sandro Poppi, who has also taken over maintenance of the snort-idmef-plugin
  (www.sourceforge.net/projects/snort-idmef), has done the most programming.
  
  Next, we'll try to write first proof-of-concept code for correlating
  idmef-messages with asset/vuln. information.
  
  Do you have some good advise, how to handle this?
  What are the best methods for comparing xml-data from different xml-docs?
  What methods shall we use for storing data (xml-db with mysql or native
  xml).
  You know, I don't want to reinvent the wheel...
  ;)
  Of course it'd be great to plug into the acid database, so that correlation
  information can be displayed within acid. We will provide an acid-output
  plugin for sure.
  
  I think I am going to use perl for the correlation-engine as a start,
  because with perl it's much easier to write proof-of-concept code when you're not
  such an advanced programmer. We can backport the code to C/C++ later.
  
  I'd be very grateful for your ideas and comments.
  
  Thanks,
  --Detmar
  
  -- 
  +++ GMX - die erste Adresse für Mail, Message, More +++
  Neu: Preissenkung für MMS und FreeMMS! http://www.gmx.net
  


------- End of Forwarded Message