impact types too general ?
"David Maciejak" <[email protected]> Wed, 11 Feb 2004 14:01:25 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
Hi, In the last draft, we have 6 impact types (admin, dos, file, recon, user, other). Don't you think 'other' group is too general ? It would be great to have more categories like in Snort or Netforensics: (I don't know how many ..) For example - virus, exploit, evasion, monitoring, policy violations could be add - admin and user type could be join in an authentication/access/authorization group (and set severity correctly) David Maciejak