Re: [Fwd: Re: [prelude-devel] [IDMEF][Issue 1] Duplicate name inclassifications (fwd)]
Herve Debar <[email protected]> Tue, 27 Jan 2004 14:43:14 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
Yoann Vandoorselaere wrote: >>Today most IDS aggregate several possible type alert behind a single >>description, as you can see Snort's doing here... >> >>CVE references CAN-1999-0517 and CAN-2002-0013 are quite different, but >>aggregated under the same "SNMP public access udp" name. >> >>Now you might argues that this should be splited up into 2 differents >>Snort rules, but it might not always be possible. > > > BTW, url and origin attribute are required. > > Now, what's the expected policy when a sensor, say a honeypot, generate > an alert triggered by some unexpected traffic but can't categorize it ? > > IMO, in this case, the honeypot should only have to fill the > classification name field... Would the proposed solution (see issue 8 discussion) satisfy you. I think it is closer to this. Hervé -- Hervé Debar <mailto:[email protected]> Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66 France Télécom R&D Fax: +33 (0)2 31 75 93 13 42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4