Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] Proposal for addition of author to standard rule listin

Subject: Re: [Snort-sigs] Proposal for addition of author to standard rule listings
Date: Wed, 03 Nov 2004 15:25:46 -0500
We're all for that here at Bleeding Snort. The only concern would be spammer harvesting of the emails, but we're all at risk from posting to the lists we participate in anyway. So that's probably a minimal extra risk.

We're almost ready to put out the web interface to the bleeding snort rules. That does include tracking as to who the owner and writer of a rule is. We'll evolve that functionality over time I'm sure.

What we hope to maintain is not necessarily just original writer, but responsible party as well. Just because a person writes a sig doesn't mean they're always be around to update as needed, or always have access to the same systems to verify with. So we hope that on the bleeding snort rules we can have at least a person that's taken responsibility for a rule if the original author is gone.

So far that's working very well informally. We hope to make that more formal with the new database interface.

Having the convention of an author in the reference field would be very nice. Great idea Frank.

Matt



Frank Knobbe wrote:
Greetings,

I would like to propose the addition of an author reference to the
rules. This is not to gloat about rules (although it might entice people
to submit rules as their name in the rule shows their active community
participation). But the main idea is to put some accountability on the
submitter in hopes to raise the quality of community submitted rules.

Since there is no "author:" tag in Snort, or a comment field, my thought
was to use the "reference:" field for that purpose. So I would like to
propose the addition of "author" as a reference type. That way rules can
be referenced to their submitter (and subsequent people that modify,
tweak and improve the rule). I envision something like
"reference:author,bmc@snort.org;".

Again, the main goals are to a) improve active participation (much like
with the documentation efforts), and b) to cause people to create better
quality rules before their name gets attached to it.

What is the thought of the community of this idea?

Regards,
Frank



-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>