Re: [prelude-devel] [IDMEF][Issue 9] Alert routing (fwd)
Herve Debar <[email protected]> Fri, 09 Jan 2004 08:27:19 +0100
| Newsgroups | gmane.ietf.idwg,gmane.comp.security.ids.prelude.devel |
|---|---|
| Organization | France Telecom R et D |
| Message-ID | <[email protected]> |
Yoann Vandoorselaere wrote: > On Thu, 2004-01-08 at 13:34, Krzysztof Zaraska wrote: >>Subject: [IDMEF][Issue 9] Alert routing >> >>Tthe draft should be more explicit on hte hierarchy between manager >>and analyzer >> >>Situation 1 (serial/transfer) >>----------- >>Imagine 3 boxes, A=analyzer, B=manager/analyzer, C=manager, connected >>thus: >> >>Analyzer-A -> (Manager-B / Analyzer-B) -> Manager-C >> >>You should ([even must ?] not have alerts on C whose analyzerid is >>Analyzer-A. > > > Herve, if I recall well about our old discussion, analyzerID can be > anything as long as it is unique across the whole IDS environment. Right. > I previously tried to express the need to be able to give a "name" to an > analyzer, and that the analyzerID field might not be the best place for > doing so as there might be real concern on checking whether a name is > unique to the whole IDS environment, and that practicaly combining > "analyzerID" + "manager analizerID", for uniqueness might not be doable > in a given implementation. I will create an issue for adding a textual name to an analyzer representation. > So, following your schema here, analyzerID will be lost once the > analyzer A alert come through the Manager B to Manager C. So how does an > user looking at an alert coming from analyzer A on Manager C refer to > the analyzer ? I have been looking at this for a long time. I have the same operational problem because people have the same alert in multiple databases, and I have come to the conclusion that: 1) either B adds value to the alert (correlation, ...) and then it's a new alert with analyzerid=B and alertid=... OR 2) B doesn't add value to the alert, and then the situation is equivalent to having A send the alert to B and C. As such, B is some sort of network router pushing alerts instead of packets, but it does not modify them. > Recording the path of an alert is something I started implementing > sometime ago in Prelude... My intent is simply to insert the interface > the alert was received on, and the interface the alert is going to be > sent to if any. I used additional data for doing this, but having > defined field withing IDMEF for that might be a better idea. Could you please phrase a proposal for altering the draft ? Hervé -- Hervé Debar <mailto:[email protected]> Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66 France Télécom R&D Fax: +33 (0)2 31 75 93 13 42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4