> Each rule has a reliability indicator and as traffic goes by the IDS maintains a score for each source.  When that threshold is exceeded then an alert is raised. In practice you would probably want to have a set of thresholds (warn, alert, critical) and you alert as an IP crosses these boundaries.
> I effectively do this by hand every day.  I look at an alert and then pull all the alerts for that IP and possibly netflow and CIF data as well. What I really need is to have the confidence in the raw alerts that I can *automatically* inform support staff "this box is infected".

We have a group of rules that we have nearly 100% confidence 
in that we specifically target - when we correlate those rules
with other indicators (EK hits, out of date Java, etc.) then the klaxons sound.

I was playing with DenyHosts the other day - specifically their 
'synchronization mode' where hosts share attacking IPs with each other
and thought it might be nice if wider information could be shared in a similar manner.

I guess it's very similar to the "Threat Intelligence" and cloud-y functions 
creeping into Next Generation Firewalls/AV/HIDS - an open standard would be nice
and obviously the 'network' could grow based on people wanting to share their
attack information - still needs infrastructure however.

