That’s actually what Eric meant. He sent me an example offline and I agreed that was better.
Allan Thomson
CTO (+1-408-331-6646)
LookingGlass Cyber Solutions
From: Jamison Day <>
Date: Tuesday, May 8, 2018 at 9:28 AM
To: Eric Johnson <>, "" <>, Allan Thomson <>
Subject: Re: [csaf] [CSAF JSON Schema] Combining "document____" properties
A nested JSON property structure may be valuable here.
e.g.
“document”: {
“tracking”: “Back to Eric"
“notes”: “Another suggested approach"
“references”: [“Eric”, “Allan”]
“distribution”: “Don’t send to Allan"
}
____________________________
Jamison M. Day, Ph.D.
Distinguished Data Scientist
Lookingglass Cyber Solutions, Inc.
303.968.0139 mobile
lookingglasscyber.com
This electronic message transmission contains information from LookingGlass Cyber Solutions, Inc. which may be attorney-client privileged, proprietary and/or confidential. The information in this
message is intended only for use by the individual(s) to whom it is addressed. If you believe that you have received this message in error, please contact the sender, delete this message, and be aware that any review, use, disclosure, copying or distribution
of the contents contained within is strictly prohibited.
On May 7, 2018 at 9:25:09 PM, Allan Thomson () wrote:
Introducing ‘/’ separation requires parsers to know what the separator character is and introduces complexity that does not exist if the properties are separately defined without
structure as you suggest.
If a product or software instance wants to create structure from those attributes that is easy done after parsing the properties into an object model/object database.
I suggest keeping the original properties.
Allan
From:
<> on behalf of Eric Johnson <>
Date: Monday, May 7, 2018 at 10:34 AM
To: "" <>
Subject: [csaf] [CSAF JSON Schema] Combining "document____" properties
I noticed, while putting together the schema, that we have "document_notes", "document_tracking", "document_references", "document_distribution".
It seems to me that these should simply be combined under one "document" property, as in:
/document/tracking
/document/notes
/document/references
/document/distribution
Any objections to this reorganization?
(Note, this stems from an observation about the CVRF documents - such a document consists of three large chunks of data - information
about the document itself, information about products, and information about vulnerabilities. Perhaps the top level properties of the JSON document should reflect that?)
Eric.