[Discussion] OISF suggestions

Victor Julien lists at inliniac.net
Wed Feb 11 09:16:14 UTC 2009


Josh Smith wrote:
> I think the administrator should have the ability to sign alerts
> created by the OISF engine with PGP.  The administrator could use the
> private/public key model so they would be able to tell if the alerts
> had been spoofed or altered.

I think this is a good suggestion, however I think it should not be part
of the engine itself. I think for alerting we want a setup similar to
Snort's unified->barnyard and I think the pgp stuff can be done in the
barnyard replacement... make sense?

Cheers,
Victor

-- 
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------




More information about the Discussion mailing list