IDMEF and UML aggregations/attributes

"Arn Vollebregt" <[email protected]> Sun, 16 Oct 2005 18:06:46 +0200
Newsgroups gmane.ietf.idwg
Message-ID <000b01c5d26b$9e0d90f0$fd01a8c0@nblvmedia01>
I have been reading through the IDMEF draft (14), and decided I wanted to
get all the UML classes into one big picture[1] for clearity. I then came
across the following questions (keep in mind that I am not a UML expert):

1) In certain classes, 'Name' seems to be used as an aggregration class and
in other classes as an attribute of a class:
Aggregration: Chapter 5.2.7.3 Figure 41 (IDMEF-message -> Alert -> Target ->
Process in .jpg).
Attribute: Chapter 5.2.4.1 Figure 14 (IDMEF-message -> Heartbeat -> Analyzer
in .jpg).
Why are these different in different classes, and why not make them all
attributes instead of aggregations?

2) Why are aggregations used and not compositions? A 'UserId' cannot excist 
without a 'User', and a composition takes care of this (either dont excist 
or be deleted when parent dies).

3) Why does 'messageid' excist as an attribute in 'Alert' and 'Heartbeat' 
when it can be in 'IDMEF-message' superclass? It will be inherited that way 
in the specialization classes.

[1] http://82.92.8.139/projects/Prelude/IDMEF-14/IDMEF-14-large.jpg (open
dir, for those who want the Visual Paradigm file as well). I know this 
diagram has some minor flaws ('Process' still needs to be linked to 
'Analyzer' for example), but I need to figure a way out to do this without 
crossing other relations and keeping the diagram readable.

Arn Vollebregt

-- 
"Wisdom lies not in obtaining knowledge, but in using it in the right way"
 - kroesjnov