From 0fc551d6803a29c1acdf937e70b5e250a3aa9362 Mon Sep 17 00:00:00 2001 From: Alexandre Dulaunoy Date: Wed, 7 Nov 2018 08:55:07 +0100 Subject: [PATCH] Update in the glossary to quickly fix the description of the IDS flag --- GLOSSARY.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/GLOSSARY.md b/GLOSSARY.md index 6923b64..a6f9af1 100644 --- a/GLOSSARY.md +++ b/GLOSSARY.md @@ -36,7 +36,8 @@ Attributes in MISP can be network indicators (e.g. IP address), system indicator ◦ A type (e.g. MD5, url) is how an attribute is described. ◦ An attribute is always in a category (e.g. Payload delivery) which puts it in a context. • A category is what describes an attribute. -◦ An IDS flag on an attribute allows to determine if an attribute can +◦ An IDS flag on an attribute allows to determine if an attribute can be automated (such as being exported as an IDS ruleset or used for detection). If the IDS flag is not present, the attribute +can be useful for contextualisation only. ## MISP Event MISP events are encapsulations for contextually linked information