Re: [IDMEF][Issue 10] Severity scale too narrow

Krzysztof Zaraska <[email protected]> Sun, 11 Jan 2004 00:33:16 +0100 (CET)
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
On Fri, 9 Jan 2004, Herve Debar wrote:

> Possibilities:
> - keep 3.

I oppose :)

> - move to five (and get appropriate definitions)

Good idea, especially if it can be kept consistant with other things...
For example, syslog has own severity scale as well...

> - something else

I was thinking about a float number within 0 - 1 range (0 - harmless, 1 -
top privilege level compromise). Very flexible, but unfortunately
a little fuzzy...

// Krzysztof Zaraska * kzaraska (at) student.uci.agh.edu.pl
// http://mops.uci.agh.edu.pl/~kzaraska/ * http://www.prelude-ids.org/
// A dream will always triumph over reality, once it is given the chance.
//		-- Stanislaw Lem