LogBlog

« Log Management Time | Main | Logging The Threat From Within »

A New Logging Standard Effort Started: Common Event Expression (CEE)

After long months of undercover work by a small team, CEE effort is ready to be open for broader involvement. Just what is CEE?  Below is an excerpt from a brochure, to be published at MITRE's site soon. I do think that the world is ready for another battle for the establishment of a logging standard, after a long string of miserable failures (see IDMEF, etc).  

"Common Event Expression (CEEā„¢): A standard log language for event interoperability in electronic systems.

CEE standardizes the way computer events are described, logged, and exchanged. By utilizing a common language and syntax, CEE takes the guesswork out of even the most menial of event- or log-related tasks. Tasks including log correlation and aggregation, enterprise-wide log management, auditing, and incident handling which once required expensive, specialized analysts or equipment can now be performed more efficiently and produce better results.

Why CEE?

If multiple systems observe the same occurrence, it should be expected that their description of that event is identical. When combined with relevant event details (time, source, destination), a computer should be able to immediately determine whether two or more logs, data logs, audit logs, alerts, alarms, or audit trails refer to the same event. In order to make this happen, there needs to be a scalable, well-defined way to express events."

We will post more details when they are ready for a public release. For now, watch an ongoing discussion about the upcoming CEE standard on the loganalysis mailing list. The thing to remember is that the standard effort is just starting up and broader industry involvement will be required. Given MITRE track record with standards such as CVE, OVAL and others, this effort has a good chance of becoming real.

Technorati tags: chuvakin, CEE, log management, logging standards

Posted April 20, 2007 in | Permalink


TrackBack

TrackBack URL for this entry:
http://www.loglogic.com/mt/mt-tb.cgi/178

Visit loglogic.com

I ♥ Logs

Subscribe to this blog’s feed RSS

November 2007
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30  
Categories
Archives
Blogroll
Blogroll
Compliance
Good Reading
LogLogic
LogLogic Partners
Sites We Watch