Re: IDMEF Draft 15

Herve Debar <[email protected]> Fri, 24 Feb 2006 16:22:41 +0100
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
[email protected] wrote:
> As GuardTower from SCS was largely one of the first SEMs developed in
>  2000 for an American Telco, we have a vested interest in the
> proceedings of this group, as does Anton. I believe that=20
> standardization in data export would go a long way in making
> ubiquitous information sharing for IPS incident response reporting.
>=20
> Unfortunately, recent changes in hardware on commerical  appliance
> IPS that scale to carrier class bandwidths ( a necessity for
> signature comparison at such speeds) have the industry moving back
> into an exclusive proprietary SIM/SEM reporting models , I suspect
> for driving revenue for their proprietary architecures reporting
> consoles/ SEMs. This appears to be really playing fits with the
> managed services providers for supporting the new IPS appliances, I
> hear. This development is really a misguided tangential direction,
> and I believe represents the reason why the attempted standardization
> for this group and the group itself's charter. Perhaps getting on
> with it.. and having IETF acceptance, is better, rather than
> perfection or agreement on the draft contents. In this way we can
> have the user community ask ( well does you IPS support the IDMEF=20
> standard for reporting Mr. IPS Vendor?, because that is a Mandatory=20
> requirement in our RFP, so we can conttinue to use our current
> SEM/SIM or choose an SEM/SIM  as seperate best of breed solution
> based on it supporting our organization's technology set.

I share pretty much all of this. I need to be able to buy my sensors and
my SIM (or SIMs) from different vendors, and all these heterogenous
components should interoperate, and integrate with the specifics of the
environment we run. I do believe that without an RFC, it will be
impossible to put a standards requirement into RFPs.

> What does this mean for IDS/IPS schema and RFC? Well point me to the=20
> latest draft and I will try to
> make an articulate evaluation, but I would hope encrypted HTTPS=20
> transmission of the sreported chema /incident datagrams
> would be in the RFC?

IDMEF is the format. IDXP is the draft that specifies secure transport.
I will send you the draft in a separate mail.

Best regards,

Herv=E9
--=20
Herv=E9 Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France T=E9l=E9com R&D              (new)Fax: +33 (0)2 31 37 83 43
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4