30 August 2011

Common Event Expression (CEE) v0.6

Common Event Expression (CEE) Architecture Specification version 0.6 has been published for comment.

Partial image of the Common Event Expression (CEE) Architecture & Components diagram from Common Event Expression (CEE) Architecture version 0.6, showing the rleationship between security event, CEE event log recommendations (CELR), the taxonomy, CEE log syntax (CLS) and CEE log transport (CLT)

As noted noted in June, CEE defines the structure and components comprising the community-developed event log standard that intends to be industry accepted and practical. The following v0.6 documents were released on 26th August 2011:

I will be having a read through these to see how they can be applied to application logging in some upcoming projects.

Feedback is sought on these documents using the CEE Email Discussion List or by email to cee@mitre.org.

Posted on: 30 August 2011 at 08:06 hrs

Comments Comments (2) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Did you ever make much progress on how to apply Common Event Expression to applicaiton logging? I came across CEE on the owasp logging cheat sheet, but I'm struggling to really wrap my head around how best to use it.

As an educational excercise I'm trying to look at OWASP's AppSensor detection points and figure out what the CEE log entry should look like. Any pointers would be appreciated.

Thanks,
Bill
1 Added by William E. Triest III Posted on 16 May 2012 at 18:47 hrs
Hi Bill

Yes, I included CEE in the [Application Security] Logging Cheat Sheet at https://www.owasp.org/index.php/Logging_Cheat_Shee... to future proof it a bit. No, I haven't attempted to create example CEE log entries, mainly because when I last had time to delve into it, I don't think it was finalised enough. But I think it has moved on now, and is an area we need to address in the new version of the AppSensor book (in progress). I have added it to the list.

I did see this article mentioned today in the CEE newsletter feed:

http://www.networkworld.com/community/node/80324

It might not help, but there are Common Event Format (CEF) examples in my presentation from AppSec EU 21011 in Dublin:

https://www.owasp.org/index.php/File:Appsensor-app...

See pages 28-31.
2 Added by Clerkendweller Posted on 17 May 2012 at 16:49 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Common Event Expression (CEE) v0.6
http://www.clerkendweller.com/2011/8/30/Common-Event-Expression-CEE-v06
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/8/30/Common-Event-Expression-CEE-v06
Requested by 184.72.184.104 on Friday, 24 May 2013 at 15:02 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2013 clerkendweller.com