RE: Question: DARPA's Common Intrusion Detection Framework (CIDF)and the IDWG effort to refine the CIDF and get it commercially accepted
"Daniel White" <[email protected]> Tue, 31 Jan 2006 13:21:48 -0600
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | Secure Commerce Systems |
| Message-ID | <[email protected]> |
Gentlemen, Having installed more ISS RealSecure/ Proventia, Snort, Cisco IDS, Juniper / Netscreen IPS, and some Enterasys ( and then there is LAncope , Intrusion .com and all the others), I believe the IDWG, in my opinion should not be disbanded, but rather evolve and be retooled with commercial IDS/IPS participation. Vulnerability science has collaborated on the CVE standard as a Widely adopted standard for vulnerability science, and the Systems Event Mgmt/System Intrusion Management market would greatly benefit with such a definition from the IDWG. I loosely monitor this working group for any industry developments and have seen more posts for dissolution recently, than I have for advancements of the field since I joined. Yet the need for such standardization (with VOIP, Bluetooth, 802.11 AG etc) developments has never been greater! How can this forum suggest dissolution? Rather should we not discuss collaboration with the industry and retooling the WG leadership / membership to be more effective, map out a strategy for goal achievement, and a plan to get there? Pardon my interpretation if it is made out of context as I have not had time to read the entire thread! ************************************************ www.securecommercesystems.com Daniel White - CEO Secure Commerce Systems PH 281 286 3342x 4 ************************************************ ***************************************************************** This email communication is confidential and may contain CONFIDENTIAL INFORMATION WHICH MAY ALSO BE LEGALLY PRIVILEGED and is intended only for the use of the intended recipients identified above. If you are not the intended recipient of this communication,you are hereby notified that any unauthorized review, use, dissemination, distribution, downloading, or copying of this communication is strictly prohibited. If you are not the intended recipient and have received this communication is error, please immediately notify us by reply email, delete this communication, and destroy all copies. ***************************************************************** -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Sam Hartman Sent: Tuesday, January 31, 2006 11:07 AM To: Chet Uber (Cox) Cc: [email protected]; [email protected]; B. Feinstein (TNT); [email protected]; [email protected]; [email protected]; [email protected]; Dr. Robert G. Rains Subject: Re: Question: DARPA's Common Intrusion Detection Framework (CIDF)and the IDWG effort to refine the CIDF and get it commercially accepted . Hi. I do sympathize with the desire to get a standardized intrusion detection format. If IDMEF and IDWG do fail, it will not prevent future efforts from being considered in the IETF or elsewhere. I would be happy to be approached by efforts that are likely to meet engineering success. However, the IETF is not an appropriate forum to "do science." In particular, the IETF is not an appropriate forum to research new proposals or to design experiments. The IRTF may be such a forum. The IETF is an appropriate forum when we get to a point where we can design standards (possibly based on research) for use in products deployed on production networks. One implication of this is that for an effort to be successful in the IETF you will need vendors who plan to implement the standard involved. If there are no such vendors, then the effort is very unlikely to succeed. Sam hartman Security Area Director