Re: [IDMEF][Issue 8] Classification and ident
Herve Debar <[email protected]> Tue, 13 Jan 2004 01:21:31 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | France Telecom R et D |
| Message-ID | <[email protected]> |
Here is my proposal for advancing the discussion on classification.
This is not a formal text change in the draft, but sort of a midway
point for general agreement.
Model:
+-------+ 1..n +--------------+ 0..n +----------------+ 0..1+----+
| Alert |<>-----|Classification|<>-----| Reference |<>---|URL |
+-------+ +--------------+ +----------------+ +----+
| STRING ident | | STRING origin |
| STRING name | | STRING meaning |
| | | STRING name |
+--------------+ +----------------+
Description
- Classification is the only mandatory piece of information,
indicating what the alert is about. It provides an identification
(pointer to previously transmitted information) and a name. The name
must be filled in and non-blank if identification is not filled.
- Reference is there for documentation purposes, to provide additional
information and naming about the Classification.
- Providing an URL for the reference is mandatory.
Rationale:
This structure is closer to the state of the art. It allows passing
classification information by reference, like source and destination,
which is useful for avoiding overload.
Problems:
- What to do if there are different "reference" sets for the same
Classification.name ?
- do we provide a namespace for origin, that allows us to get rid of
meaning ?
Comments ?
Hervé
--
Hervé Debar <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66
France Télécom R&D Fax: +33 (0)2 31 75 93 13
42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4