Re: [Fwd: Re: [prelude-devel] [IDMEF][Issue 1] Duplicate name inclassifications (fwd)]

Herve Debar <[email protected]> Tue, 27 Jan 2004 14:43:14 +0100
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>

Yoann Vandoorselaere wrote:
>>Today most IDS aggregate several possible type alert behind a single
>>description, as you can see Snort's doing here... 
>>
>>CVE references CAN-1999-0517 and CAN-2002-0013 are quite different, but
>>aggregated under the same "SNMP public access udp" name.
>>
>>Now you might argues that this should be splited up into 2 differents
>>Snort rules, but it might not always be possible.
> 
> 
> BTW, url and origin attribute are required. 
> 
> Now, what's the expected policy when a sensor, say a honeypot, generate
> an alert triggered by some unexpected traffic but can't categorize it ?
> 
> IMO, in this case, the honeypot should only have to fill the
> classification name field...

Would the proposed solution (see issue 8 discussion) satisfy you. I 
think it is closer to this.

Hervé
-- 
Hervé Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France Télécom R&D                   Fax: +33 (0)2 31 75 93 13
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4