Re: [prelude-devel] [IDMEF][Issue 10] Severity scale too narrow (fwd)
Yoann Vandoorselaere <[email protected]> Sat, 17 Jan 2004 01:17:56 +0000
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <1074302276.7447.17.camel__42428.9559400224$1074303535@arwen> |
On Fri, 2004-01-09 at 13:06, Yoann Vandoorselaere wrote: > On Fri, 2004-01-09 at 10:52, Krzysztof Zaraska wrote: > > From Krzysztof Zaraska: > > severity scale (3 grades only) is too narrow; for example, there is an > > idea floating around of expressing the danger associated with the > > attack as exp(severity*vulnerabity_level), but you can't go far this > > way with 3 level severity scale only. > > > > > > Hervé: we use 5 internally. It seems to be standard practice within > > the telco industry: > > 1) = critical > > 2) = warning > > 3) = minor > > 4) = normal > > 5) = unclassified/unclassifiable > > This wouldn't solve your graduation issue, but it actually is enough > > for an operator. We also use another scale which has 3 levels,(solved > > within 1/2 hour), (solved within 1/2 day), (solved within 1 day), but > > that's maybe too operations-oriented. > > > > IIRC, it is about the same with the Tivoli framework. I think there is > > a 0) = FATAL (i.e. system stops) in addition. [...] > > Possibilities: > > - keep 3. > > - move to five (and get appropriate definitions) > > - something else > > > > Please voice your opinion. > > IMO 3 is for sure too short. The addition of "normal" and > "unclassified/unclassifiable" would help by allowing us to send > informational events. > > Thought it still feel kinda limitative to me... Replying to myself after some thinking: IMO 5 severity is still not enough for describing different _kind_ of events with different _significant_ levels... My proposition is for the Impact class to carry a "category" attribute together with the existing "severity" attribute. As it was already stated here, it is useful for an IDS to issue _informational_ report about events going on the system. Theses report might be used later for correlation purpose. But even for here, you need to qualify how significant was an informational message. So here is the proposal : [category] 1) alert 2) informational [severity] 1) normal 2) warning 3) critical 3) unknown Please comment, -- Yoann Vandoorselaere, http://www.prelude-ids.org "Programming is a race between programmers, who try and make more and more idiot-proof software, and universe, which produces more and more remarkable idiots. Until now, universe leads the race" -- R. Cook
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBACI1E4tfUv0C+vv8RAozYAKCWcLtez+cLb+bDfbjDSEeVyUNDRACeNYou cesZwsKyDyg/o63WIyF4WVo= =WWd1 -----END PGP SIGNATURE-----