[IDMEF][Issue 10] Severity scale too narrow

Herve Debar <[email protected]> Fri, 09 Jan 2004 10:07:31 +0100
Newsgroups gmane.ietf.idwg
Organization France Telecom R et D
Message-ID <[email protected]>
 From Krzysztof Zaraska:
severity scale (3 grades only) is too narrow; for example, there is an
idea floating around of expressing the danger associated with the 
attack as exp(severity*vulnerabity_level), but you can't go far this 
way with 3 level severity scale only.


Hervé: we use 5 internally. It seems to be standard practice within 
the telco industry:
1) = critical
2) = warning
3) = minor
4) = normal
5) = unclassified/unclassifiable
This wouldn't solve your graduation issue, but it actually is enough 
for an operator. We also use another scale which has 3 levels,(solved 
within 1/2 hour), (solved within 1/2 day), (solved within 1 day), but 
that's maybe too operations-oriented.

IIRC, it is about the same with the Tivoli framework. I think there is 
a 0) = FATAL (i.e. system stops) in addition.




Possibilities:
- keep 3.
- move to five (and get appropriate definitions)
- something else

Please voice your opinion.

Hervé
-- 
Hervé Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France Télécom R&D                   Fax: +33 (0)2 31 75 93 13
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4