RE: IDMEF Draft 15
"Anton Chuvakin" <[email protected]> Wed, 15 Feb 2006 23:06:02 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | netForensics, Inc |
| Message-ID | <00f201c632ae$4d0e5100$876ad8d8@achuvakin100> |
All, >By 25 February, we would like to get all applicable comments. Again, we are not making changes to the substance of the document, but rather just cleaning up an typo type problems. >Once we are done with the document, we will ask that it be published as an experimental rfc. So, IDMEF is officially "dead" then? IDS might not be dead, but IDMEF largely is... I haven't posted to this list that much, but I've been watching IDMEF for many years. In fact, netForensics nFX SIM solutions's early XML event tranfer protocol, defined back in 2000, was loosely inspired by the IDMEF. However, IDMEF always was and remains largely unsuitable for our purposes, and I suspect other vendors in the SIM/SIEM/correlation space would agree with me. And so would the IDS (now IPS, for the most part) vendors. The issues are too numerous to list here. Even something as basic as alert vs hearbeart distinction raises some questions. One area where I can see shreds of IDMEF surviving is cross-organizational data sharing. A little problem with this is that it largely does not exist... I can see how a hybrid of IDMEF and IODEF with inherent and well-defined data sanitization might come handy. Other than that, utilization of IDMEF in four other use cases (from the page 4 of the doc) is totally irrelevant and is being better addressed by other means. Best, -- Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA - http://www.chuvakin.org Chief Security Strategist Product Management Group netForensics - http://www.netForensics.com 732-393-6071