Skip to content

IDMEFv2 : Source Class Comments

Gilles Lehmann edited this page Jan 6, 2023 · 6 revisions

The Source class describes the source(s) of the event(s) leading up to the alert.In this context, the Source always refers to the attacker, which may be different from the source in the context of a network connection. For instance, when a user connects to a webserver spreading malwares, the webserver will be listed as the IDMEF Source, even though it was initially the destination of the underlying HTTP(S) connection.

TBM: I suggest changing the word "attacker" by "origin". Incident are not always "attacks". Maybe the name of the Source Class should also be replaced by "Origin" which is wider. Another proposition is to change the Target name so it wouldn't imply a voluntary attack. A choice used elsewhere is "Impacted" although this term is not very intuitive. (or destination)

                                   +------------------------+  
                                   |         Source         |  
                                   +------------------------+  
                                   | IP         IP          |  
                                   | STRING     Hostname    |  
                                   | STRING     Note        |  
                                   | STRING[]   TI          |  
                                   | STRING     User        |  
                                   | EMAIL      Email       |  
                                   | PROTOCOL[] Protocol    |  
                                   | INT[]      Port        |  
                                   | GEOLOC     GeoLocation |  
                                   | UNLOCODE   UnLocation  |  
                                   | STRING     Location    |  
                                   | ID[]       Attachment  |  
                                   | ID[]       Observable  |  
                                   +------------------------+  

IP

Optional. Source IP address.

Hostname

Optional. Hostname of this source. This SHOULD be a fully qualified domain name, but may not conform exactly because values extracted from logs, messages, DNS, etc. may themselves be malformed.An empty string MAY be used to explicitly state that this value was inquired but not found (missing DNS entry).

Note

Optional. Free text human-readable additional note for this source.

TI

Optional. Threat Intelligence data about the source. Values in this list MUST use the format "attribute:origin", where "attribute" refers to the attribute inside this source found inside a Threat Intelligence database, and "origin" contains a short identifier for the Threat Intelligence database. E.g. "IP:Dshield".Please note that the same attribute may appear multiple times inside the list (because a match was found in multiple Threat Intelligence databases).

User

Optional. User ID or login responsible for the alert.

Email

Optional. Email address responsible for the alert. E.g. the value of the "Reply-To" or "From" header inside a phishing e-mail.

Protocol

Optional. Protocols related to connections from/to this source. If several protocols are stacked, they MUST be ordered from the lowest (the closest to the medium) to the highest (the closest to the application) according to the ISO/OSI model.

Port

Optional. Source ports involved in the alert. Values in this list MUST be integers and MUST be in the range 1-65535.

GeoLocation

Optional. GPS coordinates for the source.

UnLocation

Optional. Standard UN/Locode for the source.

Location

Optional. Internal name for the location of the source.

Comments:

  • For an "IT" source the location can define an internal network.
  • Should there be an attribute "Internal" (false/true) to indicate if the source is internal to the organisation ? This information is important to measure the gravity of a potential incident may it be cyber or physical. If the source is internal it means that the "attacker" is already inside which might make a big difference. It also gives an indication of urgency and what counter-measure can be taken

Attachment

Optional. Identifiers for attachments related to this source. Each identifier listed here MUST match the "Name" attribute for one of the attachments described using the Attachment class (Section 4.8).

Observable

Optional. Identifiers for observables related to this source. Each identifier listed here MUST match the "Name" attribute for one of the observables described using the Observable class (Section 4.9).

Clone this wiki locally