metron-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From cestella <...@git.apache.org>
Subject [GitHub] incubator-metron pull request #426: METRON-675: Make Threat Triage rules abl...
Date Thu, 26 Jan 2017 16:33:28 GMT
GitHub user cestella opened a pull request:

    https://github.com/apache/incubator-metron/pull/426

    METRON-675: Make Threat Triage rules able to be assigned names and comments

    There may be many, many threat triage rules. To help organize these, we should make them
slightly more complex than a simple key/value as we have it now. We should add optional name
and optional comment fields.
    
    This essentially makes the risk level rules slightly more complex.  The format goes from:
    ```
    "riskLevelRules" : {
      "stellar expression" : numeric score
    }
    ```
    to:
    ```
    "riskLevelRules" : [
      {
         "name" : "optional name",
         "comment" : "optional comment",
         "rule" : "stellar expression",
         "score" : numeric score
      }
    ]
    ```
    This is NOT backwards compatible, but I think it's more explicit and a bit more clear.
    
    Testing plan to come in a follow-on comment.

You can merge this pull request into a Git repository by running:

    $ git pull https://github.com/cestella/incubator-metron METRON-675

Alternatively you can review and apply these changes as the patch at:

    https://github.com/apache/incubator-metron/pull/426.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

    This closes #426
    
----
commit 2d9c129e2be95d635d5c014415087b7a13a678db
Author: cstella <cestella@gmail.com>
Date:   2017-01-26T16:15:01Z

    METRON-675: Add name and description to threat triage rules.

commit 8639d9967afb2add2035aa57fa60d4cc17cbb117
Author: cstella <cestella@gmail.com>
Date:   2017-01-26T16:21:34Z

    forgot license

----


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at infrastructure@apache.org or file a JIRA ticket
with INFRA.
---

Mime
View raw message