Re: [IDMEF][Issue 8] Classification and ident

Herve Debar <[email protected]> Tue, 13 Jan 2004 01:21:31 +0100
Newsgroups gmane.ietf.idwg
Organization France Telecom R et D
Message-ID <[email protected]>
Here is my proposal for advancing the discussion on classification. 
This is not a formal text change in the draft, but sort of a midway 
point for general agreement.

Model:

+-------+ 1..n  +--------------+ 0..n  +----------------+ 0..1+----+
| Alert |<>-----|Classification|<>-----| Reference      |<>---|URL |
+-------+       +--------------+       +----------------+     +----+
                 | STRING ident |       | STRING origin  |
		| STRING name  |       | STRING meaning |
		|              |       | STRING name    |
                 +--------------+       +----------------+

Description
- Classification is the only mandatory piece of information, 
indicating what the alert is about. It provides an identification 
(pointer to previously transmitted information) and a name. The name 
must be filled in and non-blank if identification is not filled.
- Reference is there for documentation purposes, to provide additional 
information and naming about the Classification.
- Providing an URL for the reference is mandatory.

Rationale:
This structure is closer to the state of the art. It allows passing 
classification information by reference, like source and destination, 
which is useful for avoiding overload.

Problems:
- What to do if there are different "reference" sets for the same 
Classification.name ?
- do we provide a namespace for origin, that allows us to get rid of 
meaning ?

Comments ?

Hervé
-- 
Hervé Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France Télécom R&D                   Fax: +33 (0)2 31 75 93 13
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4