← Prev in month ← Prev in thread

Next Face 2 Face

From
Sarah Kelley <>
Date
2016-02-04T14:03:00+00:00
ID
Thread
Next Face 2 Face
Unfortunately, I can’t say with 100% certainty. The STIX documents were sent via email, so I don’t have a clue what created the documents from a tool perspective.
I feel like some of it is that people are just taking liberties with the language. For example, one error I just got when trying to validate a file said:
“The value ‘Domain Name’ is not an element of the set {‘FQDN’, ‘TLD’}”
This says to me, and I could just be wrong, that someone implemented something that didn’t like the options of FQDN or TLD, so they just put Domain Name there instead.
However, some of the problems might be just an issue reading/interpreting the specs. I have also seen the error:
“Element ‘{ http://stix.mitre.org/stix-1 }Handling’ is not a member of…” however “{ http://stix.mitre.org/Indicator-2}Handling ” is one of the options in the  list. Since I’m an analyst and not a spec writer or a tool developer, this error doesn’t mean much to me, but it might mean something to others.
Sorry I can’t provide more specifics, but I really don’t know how these documents were generated.
Sarah Kelley
Senior CERT Analyst
Center for Internet Security (CIS)

Integrated Intelligence Center (IIC)

Multi-State Information Sharing and Analysis Center (MS-ISAC)
1-866-787-4722 (7×24 SOC)
Email:  
www.cisecurity.org
Follow us @CISecurity
From:  < 
> on behalf of Jason Keirstead < 
>
Date:  Thursday, February 4, 2016 at 8:48 AM
To:  Eric Burger < 
>
Cc:  Sarah Kelley <  >, "  " < 
>
Subject:  Re: [cti] Quality of the specs
Furthermore - are the people creating this STIX using a tool provided by a vendor, or crafting it by hand (or using home grown tools).
-  Jason Keirstead  STSM, Product Architect, Security Intelligence, IBM Security Systems  www.ibm.com/security
www.securityintelligence.com
Without data, all you are is just another person with an opinion - Unknown
Eric Burger  ---02/04/2016 07:20:43 AM---In your experience is it that people are not reading the specs, the specs are ambiguous, the specs a
From:
Eric Burger < 
>
To:
Sarah Kelley < 
>
Cc:
"  " < 
>
Date:
02/04/2016 07:20 AM
Subject:
[cti] Quality of the specs
Sent by:
< 
>
In your experience is it that people are not reading the specs, the specs are ambiguous, the specs are wrong, or the validator is wrong?
On Feb 2, 2016, at 2:53 PM, Sarah Kelley <

> wrote:
Can I make a request that every training that takes place regarding STIX/TAXII/CybOX specifically mention/provide training on the STIX validator? We have had several different instances where people attempt to share information with us  in STIX format, but the STIX doesn’t validate so we can’t actually use what they’re sending us.
...
This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify  the sender immediately and permanently delete the message and any attachments.
. . .
← Prev in month ← Prev in thread