IDMEF and UML aggregations/attributes
"Arn Vollebregt" <[email protected]> Sun, 16 Oct 2005 18:06:46 +0200
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <000b01c5d26b$9e0d90f0$fd01a8c0@nblvmedia01> |
I have been reading through the IDMEF draft (14), and decided I wanted to
get all the UML classes into one big picture[1] for clearity. I then came
across the following questions (keep in mind that I am not a UML expert):
1) In certain classes, 'Name' seems to be used as an aggregration class and
in other classes as an attribute of a class:
Aggregration: Chapter 5.2.7.3 Figure 41 (IDMEF-message -> Alert -> Target ->
Process in .jpg).
Attribute: Chapter 5.2.4.1 Figure 14 (IDMEF-message -> Heartbeat -> Analyzer
in .jpg).
Why are these different in different classes, and why not make them all
attributes instead of aggregations?
2) Why are aggregations used and not compositions? A 'UserId' cannot excist
without a 'User', and a composition takes care of this (either dont excist
or be deleted when parent dies).
3) Why does 'messageid' excist as an attribute in 'Alert' and 'Heartbeat'
when it can be in 'IDMEF-message' superclass? It will be inherited that way
in the specialization classes.
[1] http://82.92.8.139/projects/Prelude/IDMEF-14/IDMEF-14-large.jpg (open
dir, for those who want the Visual Paradigm file as well). I know this
diagram has some minor flaws ('Process' still needs to be linked to
'Analyzer' for example), but I need to figure a way out to do this without
crossing other relations and keeping the diagram readable.
Arn Vollebregt
--
"Wisdom lies not in obtaining knowledge, but in using it in the right way"
- kroesjnov