[IDMEF][Issue 10] Severity scale too narrow
Herve Debar <[email protected]> Fri, 09 Jan 2004 10:07:31 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | France Telecom R et D |
| Message-ID | <[email protected]> |
From Krzysztof Zaraska: severity scale (3 grades only) is too narrow; for example, there is an idea floating around of expressing the danger associated with the attack as exp(severity*vulnerabity_level), but you can't go far this way with 3 level severity scale only. Hervé: we use 5 internally. It seems to be standard practice within the telco industry: 1) = critical 2) = warning 3) = minor 4) = normal 5) = unclassified/unclassifiable This wouldn't solve your graduation issue, but it actually is enough for an operator. We also use another scale which has 3 levels,(solved within 1/2 hour), (solved within 1/2 day), (solved within 1 day), but that's maybe too operations-oriented. IIRC, it is about the same with the Tivoli framework. I think there is a 0) = FATAL (i.e. system stops) in addition. Possibilities: - keep 3. - move to five (and get appropriate definitions) - something else Please voice your opinion. Hervé -- Hervé Debar <mailto:[email protected]> Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66 France Télécom R&D Fax: +33 (0)2 31 75 93 13 42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4