OTRF / OSSEM

Open Source Security Events Metadata (OSSEM)
MIT License
1.22k stars 212 forks source link

Update OSSEM CDM source, destination or target guideline #121

Closed Cyb3rWard0g closed 2 years ago

Cyb3rWard0g commented 2 years ago

Several events that the OSSEM CDM project describes have a sense of direction.

Usually in a network connection, this sense of direction is represented by source and destination to describe the origin of the connection and where the network packets are sent to. This concept of direction is not only represented in a network connection, but also other events such as creation of a process where an entity interacts with another entity. Therefore, the OSEEM project is also using the concept of target instead of destination when describing an interaction between entities that are not part of a network connection.

We need to provide some documentation for these use cases.