[101615] in North American Network Operators' Group
Re: Stupid Question: Network Abuse RFC?
daemon@ATHENA.MIT.EDU (Stephane Bortzmeyer)
Mon Jan 14 08:23:21 2008
Date: Mon, 14 Jan 2008 14:22:00 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: Christopher Morrow <christopher.morrow@gmail.com>
Cc: Paul Ferguson <fergdawg@netzero.net>, nanog@nanog.org
In-Reply-To: <75cb24520801122158r298c348eob808c41ebd8d5100@mail.gmail.com>
Errors-To: owner-nanog@merit.edu
On Sun, Jan 13, 2008 at 12:58:11AM -0500,
Christopher Morrow <christopher.morrow@gmail.com> wrote
a message of 21 lines which said:
> There was also some work ongoing in INCH, that included some
> machine-parsable reporting formats
For the technical side of abuse reporting, IETF documents two formats:
The Intrusion Detection Message Exchange Format (IDMEF), RFC 4765,
with a status of Experimental
The Incident Object Description Exchange Format (IODEF), RFC 5070,
which is Standard.