[IDMEF][Issue 5] duplicate information related to protocol information.
Herve Debar <[email protected]> Thu, 08 Jan 2004 17:46:43 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | France Telecom R et D |
| Message-ID | <[email protected]> |
The current draft allow specification of tcp or udp as protocol only.
This is a problem for other protocols. Moreover, the information can
be inserted in two places, in source and destination, and there is no
constraint ensuring that they should be the same.
I somehow think that the protocol should be something like:
<Protocol ip_version=[number] iana_number=[number] iana_name=[free
text] >some text</Protocol>
That way we would have any IP protocol represented.
I haven't yet made my mind where to attach this protocol information.
From Krzysztof Zaraska ->
The problem is that we are usually dealing with a protocol stack.
Therefore, what about the layer 2 information for example? Ethernet
addresses can go into into Source/Target, but what about, say, VPI/VCI
fields in ATM, or any other connection identifier? [This is not an
academic problem, as some people are trying to combine Prelude with
logging all traffic at the session level for later inspection and
would appreciate some form of connection identifier within the alert.]
I see this as actually 2 problems, although I blend them in one for
the moment because they may have the same solution:
1) duplicate, possibly incoherent, information in messages.
2) inability to represent anything else than TCP and UDP. I think that
at least for ICMP it's a shame.
Hervé
--
Hervé Debar <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66
France Télécom R&D Fax: +33 (0)2 31 75 93 13
42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4