RE: IDMEF Draft 15

"Anton Chuvakin" <[email protected]> Wed, 15 Feb 2006 23:06:02 -0500
Newsgroups gmane.ietf.idwg
Organization netForensics, Inc
Message-ID <00f201c632ae$4d0e5100$876ad8d8@achuvakin100>
All,

>By 25 February, we would like to get all applicable comments.  Again, we
are not making changes to the substance of the document, but rather just
cleaning up an typo type problems.  
>Once we are done with the document, we will ask that it be published as an
experimental rfc. 

So, IDMEF is officially "dead" then? IDS might not be dead, but IDMEF
largely is... I haven't posted to this list that much, but I've been
watching IDMEF for many years. In fact, netForensics nFX SIM solutions's
early XML event tranfer protocol, defined back in 2000, was loosely inspired
by the IDMEF. However, IDMEF always was and remains largely unsuitable for
our purposes, and I suspect other vendors in the SIM/SIEM/correlation space
would agree with me. And so would the IDS (now IPS, for the most part)
vendors. The issues are too numerous to list here. Even something as basic
as alert vs hearbeart distinction raises some questions. 

One area where I can see shreds of IDMEF surviving is cross-organizational
data sharing. A little problem with this is that it largely does not
exist... I can see how a hybrid of IDMEF and IODEF with inherent and
well-defined data sanitization  might come handy. Other than that,
utilization of IDMEF in four other use cases (from the page 4 of the doc) is
totally irrelevant and is being better addressed by other means.

Best,
-- 
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA - http://www.chuvakin.org 
Chief Security Strategist 
Product Management Group 
netForensics - http://www.netForensics.com
732-393-6071