SDEE vs IDMEF ?
From: Sebastien Tricaud (toady_at_gscore.org)
Date: 03/11/04
- Previous message: John Bedrick: "Re: Entercept HIDS Question"
- Next in thread: Kohlenberg, Toby: "RE: SDEE vs IDMEF ?"
- Maybe reply: Kohlenberg, Toby: "RE: SDEE vs IDMEF ?"
- Reply: Rob Shein: "RE: SDEE vs IDMEF ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: focus-ids@securityfocus.com Date: Wed, 10 Mar 2004 23:25:31 -0800
Hi everybody,
According to this press release:
http://www.trusecure.com/company/press/pr_20040223.shtml
SDEE is a Network Intrusion Detection System Alert Format.
However, there's already IDMEF (Intrusion Detection Message Exchange
Format) for that purpose. You can find the latest IDMEF draft there:
http://www1.ietf.org/internet-drafts/draft-ietf-idwg-idmef-xml-11.txt
IDMEF will become standardized shortly, I wonder why Cisco, ISS and
Sourcefire joined their forces to do something similar. Any idea ?
Thanks,
Sebastien.
- application/pgp-signature attachment: This is a digitally signed message part
- Previous message: John Bedrick: "Re: Entercept HIDS Question"
- Next in thread: Kohlenberg, Toby: "RE: SDEE vs IDMEF ?"
- Maybe reply: Kohlenberg, Toby: "RE: SDEE vs IDMEF ?"
- Reply: Rob Shein: "RE: SDEE vs IDMEF ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|