{"id":27,"date":"2023-03-10T21:25:11","date_gmt":"2023-03-10T21:25:11","guid":{"rendered":"http:\/\/192.168.0.7\/wordpress\/?page_id=27"},"modified":"2023-03-28T21:47:54","modified_gmt":"2023-03-28T21:47:54","slug":"genesis-and-history","status":"publish","type":"page","link":"https:\/\/192.168.0.7\/wordpress\/index.php\/genesis-and-history\/","title":{"rendered":"IDMEFv2 Genesis and history"},"content":{"rendered":"\n
During nearly ten years, the Intrusion Detection Working Group worked on the definition of the IDMEF format. <\/p>\n\n\n\n
The purpose of the Intrusion Detection Message Exchange Format (IDMEF) is to define data formats and exchange procedures for sharing
information of interest to intrusion detection and response systems and to the management systems that may need to interact with them.<\/p>\n\n\n\n
Among others, companies like Boeing, Mitre, Nokia, Cisco and MIT participate to the elaboration of the RFC 4765<\/p>\n\n\n\n
In 2007, the standardization has not been completely achieved but three experimental RFCs were published :<\/p>\n\n\n\n
IDMEFv1 has been adopted in open-source probes ( suricata, ossec, samhain, snort, etc.) and in Prelude OSS.<\/p>\n\n\n\n
In 2015 the SECEF (SECurity Exchange Format) consortium was created to improve and promote IDMEFv1. The SECEF consortium was composed of people who wrote the RFC 4765 as well as people who implemented IDMEFv1 in Prelude OSS and Prelude SIEM (the former development team)<\/p>\n\n\n\n
After two years of analysis and test, the conclusion was that the format needed more than just few modifications. The base was solid but needed to be totally re-thinked.<\/p>\n\n\n\n
Although it has proven it’s efficacy, IDMEFv1 has defaults among which:<\/p>\n\n\n\n
2020 SECEF2 : IDMEFV2 new version and standardization goal<\/p>\n\n\n\n
In 2020 the SECEF2 (SECurity Exchange Format) consortium was created to create a new version of the format and standardize it.<\/p>\n\n\n\n
SECEF2 consortium is an enlargement of the SECEF1 consortium with new industrial members.<\/p>\n\n\n\n
The first step of the project was to experiment a new version of IDMEFv2 for protection of combined and complex threat on cyber and physical infrastructures.<\/p>\n\n\n\n
This experimentation has been done on real scale in five different prototypes in the H2020 7SHIELD research project<\/p>\n\n\n\n
The major results and decisions for IDMEFv2 were:<\/p>\n\n\n\n
1998 – 2007 : IDMEFv1 During nearly ten years, the Intrusion Detection Working Group worked on the definition of the IDMEF format. The purpose of the Intrusion Detection Message Exchange Format (IDMEF) is to define data formats and exchange procedures for sharinginformation of interest to intrusion detection and response systems and to the management systems… Read More »IDMEFv2 Genesis and history<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":""},"yoast_head":"\n