possible work item

From
Terry MacDonald <>
Date
2015-10-26T20:18:00+00:00
ID
Thread
possible work item
As a quick throwaway question – would moving to JSON-LD help us ‘map’ our data to OpenTPX or ThreatExchange? My thoughts are that if
  all three parties can agree to use JSON-LD then it becomes VERY easy to translate the data from one JSON format to another.



Cheers



Terry MacDonald

Senior STIX Subject Matter Expert

SOLTRA
   An FS-ISAC and DTCC Company

+61 (407) 203 206
  
From:
 [mailto:]
  On Behalf Of  Davidson II, Mark S
  Sent:  Tuesday, 27 October 2015 12:25 AM
To:  Jerome Athias <>; Jordan, Bret <>
Cc:  
Subject:  RE: [cti-interoperability] possible work item



(This is really just a somewhat different framing, but I’ll put it in my own words)



I’d like to propose that the interoperability SC maintain awareness of related efforts and promote collaboration between the CTI TC and related efforts
  wherever possible. Specifically, I feel that treating e.g., OpenTPX and ThreatExchange as friendly will be mutually beneficial.



I realize this probably pushes the boundary of the term interoperability; if it doesn’t fit in the interop SC, maybe it’s just something we take
  on at the TC level.



Thank you.

-Mark
From:
    [ mailto: ]
  On Behalf Of  Jerome Athias
  Sent:  Friday, October 23, 2015 2:16 PM
To:  Jordan, Bret < 
>
Cc:

Subject:  Re: [cti-interoperability] possible work item



Yeah. At the same time they could be easily challenged, because frankly speaking (Sean could kick my ass), I don't need a new-cool-fancy format to get dshield and malware domains lists integrated
  in my SIEM. CSV is fine

 On Friday, 23 October 2015, Jordan, Bret < 
> wrote:

One thing I would like to see this group work on is:



* Outreach...  Meaning I would like to have us do outreach to the new OpenTPX group and the Facebook ThreatExchange group and see what kind of give-n-take would be needed for us to combine efforts.



From looking at it, I am guessing that each group would need to give a little. But I think a unified solution would be greater than the sum of the parts.  Yes, it will challenge some of the
  things we have done in STIX, but some of the things in OpenTPX and FB ThreatExchange are neat.  And we should really look in to doing them.





Thanks,



Bret







Bret Jordan CISSP

Director of Security Architecture and Standards
Office of the CTO

Blue Coat Systems

PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050

"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."