[Discussion] OISF suggestions
Victor Julien
lists at inliniac.net
Wed Feb 11 09:16:14 UTC 2009
Josh Smith wrote:
> I think the administrator should have the ability to sign alerts
> created by the OISF engine with PGP. The administrator could use the
> private/public key model so they would be able to tell if the alerts
> had been spoofed or altered.
I think this is a good suggestion, however I think it should not be part
of the engine itself. I think for alerting we want a setup similar to
Snort's unified->barnyard and I think the pgp stuff can be done in the
barnyard replacement... make sense?
Cheers,
Victor
--
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------
More information about the Discussion
mailing list