RE: IDMEF Draft 15

"Anton Chuvakin, Ph.D." <[email protected]> Thu, 23 Feb 2006 11:59:47 -0500 (EST)
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
I am wondering if this message to the list actually got thru. If it did, 
IDMEF is truly dead since nobody even bothered to respond to the comments 
about its death...

> All,
>
>> By 25 February, we would like to get all applicable comments.  Again, we
> are not making changes to the substance of the document, but rather just
> cleaning up an typo type problems.
>> Once we are done with the document, we will ask that it be published as an
> experimental rfc.
>
> So, IDMEF is officially "dead" then? IDS might not be dead, but IDMEF
> largely is... I haven't posted to this list that much, but I've been
> watching IDMEF for many years. In fact, netForensics nFX SIM solutions's
> early XML event tranfer protocol, defined back in 2000, was loosely inspired
> by the IDMEF. However, IDMEF always was and remains largely unsuitable for
> our purposes, and I suspect other vendors in the SIM/SIEM/correlation space
> would agree with me. And so would the IDS (now IPS, for the most part)
> vendors. The issues are too numerous to list here. Even something as basic
> as alert vs hearbeart distinction raises some questions.
>
> One area where I can see shreds of IDMEF surviving is cross-organizational
> data sharing. A little problem with this is that it largely does not
> exist... I can see how a hybrid of IDMEF and IODEF with inherent and
> well-defined data sanitization  might come handy. Other than that,
> utilization of IDMEF in four other use cases (from the page 4 of the doc) is
> totally irrelevant and is being better addressed by other means.
>
> Best,
>

-- 
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA - http://www.chuvakin.org
Chief Security Strategist
Product Management Group
netForensics -  http://www.netForensics.com
732-393-6071
**************************************************************************************************
The contents of this email and any attachments are confidential.
They are intended for the named recipient(s) only.
If you have received this email in error please notify the system manager or  the 
sender immediately and do not disclose the contents to anyone or make copies.

** This e-mail  has been scanned for viruses, vandals and malicious content. **
**************************************************************************************************