Re: IDMEF Draft 15

Herve Debar <[email protected]> Fri, 24 Feb 2006 09:47:09 +0100
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
Anton Chuvakin, Ph.D. wrote:
> I am wondering if this message to the list actually got thru. If it did=
,
> IDMEF is truly dead since nobody even bothered to respond to the
> comments about its death...

Well, it did go to the list, but I'm not sure there is much to respond
to. You are voicing your opinion, which is fair enough, and at the same
time not being specific enough to enable a response, IMO. And I'm really
not interested in a flamefest at this stage.

>> All,
>>
>>> By 25 February, we would like to get all applicable comments.  Again,=
 we
>> are not making changes to the substance of the document, but rather ju=
st
>> cleaning up an typo type problems.
>>> Once we are done with the document, we will ask that it be published
>>> as an
>> experimental rfc.
>>
>> So, IDMEF is officially "dead" then? IDS might not be dead, but IDMEF
>> largely is... I haven't posted to this list that much, but I've been
>> watching IDMEF for many years. In fact, netForensics nFX SIM solutions=
's
>> early XML event tranfer protocol, defined back in 2000, was loosely
>> inspired
>> by the IDMEF. However, IDMEF always was and remains largely unsuitable
>> for
>> our purposes, and I suspect other vendors in the SIM/SIEM/correlation
>> space
>> would agree with me. And so would the IDS (now IPS, for the most part)
>> vendors. The issues are too numerous to list here. Even something as
>> basic
>> as alert vs hearbeart distinction raises some questions.

There are SIM environments using IDMEF, commercially.

>> One area where I can see shreds of IDMEF surviving is
>> cross-organizational
>> data sharing. A little problem with this is that it largely does not
>> exist... I can see how a hybrid of IDMEF and IODEF with inherent and
>> well-defined data sanitization  might come handy. Other than that,
>> utilization of IDMEF in four other use cases (from the page 4 of the
>> doc) is
>> totally irrelevant and is being better addressed by other means.

As far as I can tell, INCH is also nearing completion, so again you may
be late bringing in comments.

Herv=E9
--=20
Herv=E9 Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France T=E9l=E9com R&D              (new)Fax: +33 (0)2 31 37 83 43
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4