RE: Question: DARPA's Common Intrusion Detection Framework (CIDF)and the IDWG effort to refine the CIDF and get it commercially accepted

"Daniel White" <[email protected]> Tue, 31 Jan 2006 13:21:48 -0600
Newsgroups gmane.ietf.idwg
Organization Secure Commerce Systems
Message-ID <[email protected]>
Gentlemen,


Having installed more ISS RealSecure/ Proventia, Snort, Cisco IDS,
Juniper / Netscreen IPS, and some Enterasys ( and then there is LAncope ,
Intrusion .com and all the others), I believe the IDWG, in my opinion should
not be disbanded, but rather evolve and be retooled with commercial IDS/IPS
participation.

Vulnerability science has collaborated on the CVE standard as a
Widely adopted standard for vulnerability science, and the Systems Event
Mgmt/System Intrusion Management market would greatly benefit
with such a definition from the IDWG. 

I loosely monitor this working group for any industry developments
 and have seen more posts for dissolution recently, than I have for
 advancements of the field since I joined.

Yet the need for such standardization (with VOIP, Bluetooth, 802.11 AG etc)
developments has never been greater! How can this forum suggest dissolution?
Rather should we not discuss collaboration with the industry and retooling
the WG leadership / membership to be more effective, map out a strategy for
goal achievement, and a plan to get there?

Pardon my interpretation if it is made out of context as I have not had time
to read the entire thread!


************************************************
www.securecommercesystems.com
Daniel White  - CEO
Secure Commerce Systems
PH 281 286 3342x 4
************************************************
*****************************************************************
This email communication is confidential and may contain
CONFIDENTIAL INFORMATION WHICH MAY ALSO BE LEGALLY PRIVILEGED and is
intended only for the use of the
intended recipients identified above. If you are not the 
intended recipient of this communication,you are hereby 
notified that any unauthorized review, use, dissemination, 
distribution, downloading, or copying of this communication 
is strictly prohibited. If you are not the intended recipient and 
have received this communication is error, please immediately 
notify us by reply email, delete this communication, and 
destroy all copies.

*****************************************************************

-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of Sam
Hartman
Sent: Tuesday, January 31, 2006 11:07 AM
To: Chet Uber (Cox)
Cc: [email protected]; [email protected]; B. Feinstein (TNT);
[email protected]; [email protected]; [email protected];
[email protected]; Dr. Robert G. Rains
Subject: Re: Question: DARPA's Common Intrusion Detection Framework
(CIDF)and the IDWG effort to refine the CIDF and get it commercially
accepted



.  Hi.  I do sympathize with the desire to get a standardized
intrusion detection format.

If IDMEF and IDWG do fail, it will not prevent future efforts from
being considered in the IETF or elsewhere.

I would be happy to be approached by efforts that are likely to meet
engineering success.

However, the IETF is not an appropriate forum to "do science."  In
particular, the IETF is not an appropriate forum to research new
proposals or to design experiments.  The IRTF may be such a forum.

The IETF is an appropriate forum when we get to a point where we can
design standards (possibly based on research) for use in products
deployed on production networks.

One implication of this is that for an effort to be successful in the
IETF you will need vendors who plan to implement the standard
involved.  If there are no such vendors, then the effort is very
unlikely to succeed.


Sam hartman
Security Area Director