Re: [IDMEF][Issue 10] Severity scale too narrow
Krzysztof Zaraska <[email protected]> Sun, 11 Jan 2004 00:33:16 +0100 (CET)
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 9 Jan 2004, Herve Debar wrote: > Possibilities: > - keep 3. I oppose :) > - move to five (and get appropriate definitions) Good idea, especially if it can be kept consistant with other things... For example, syslog has own severity scale as well... > - something else I was thinking about a float number within 0 - 1 range (0 - harmless, 1 - top privilege level compromise). Very flexible, but unfortunately a little fuzzy... // Krzysztof Zaraska * kzaraska (at) student.uci.agh.edu.pl // http://mops.uci.agh.edu.pl/~kzaraska/ * http://www.prelude-ids.org/ // A dream will always triumph over reality, once it is given the chance. // -- Stanislaw Lem