Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-28-2011, 01:27 AM
Brian Newman
Guest
 
Posts: n/a
Default SCAP and organizing useless data

I've been tinkering with building a security reporting tool based on
SCAP. I'm running into some real problems though and I'm hoping
somebody can point me in the right direction.
Namely, I can't seem to find any actually useful data in SCAP format.
Here's a specific example of what I'm talking about..If you pull the
XCCDF for the vista firewall from the National Vulnerability Database,
you'll find a ton of rules of the form, "The log file size limit for
the Windows Firewall should be configured correctly for the Domain
Profile." What does "configured correctly" mean? The XCCDF doesn't
tell you. The XCCDF does provide a CCE, but the CCE list doesn't say
anything actually useful either. It says, "The log file size limit
for the Windows Firewall should be configured correctly for the Domain
Profile.". You have to actually go digging through the web to find out
what "configured correctly" means - which makes this XCCDF and CCE
useless. If I'm going to have to dig through the web anyway to
understand a configuration issue (similar problems exist for CVEs as
well), then SCAP isn't really saving me a great deal of effort. The
value of SCAP is supposed to be in organizing and distributing
security information.

I don't know who decided it'd be a good idea to create a common
standard in which to put useless information. I can't quite see it as
making progress.

I can only assume that I've been looking in the wrong places for SCAP
data and that there's actually something worthwhile out there
organized in a meaningful and computer friendly way. If so, I'd be
eternally grateful if somebody can point me to it.

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:12 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45