← Prev in month ← Prev in thread

Need for Investigation/Tag object?

From
Terry MacDonald <>
Date
2015-10-27T20:03:39+00:00
ID
Thread
Need for Investigation/Tag object?
Hi All,

 

Sarah’s email below reminded me of some thoughts that have been bubbling around for a while.

 

I think there is a need for us to support describing and sharing Threat intelligence while it is still under investigation. Historically
 STIX has been used by Organizations who are generally sharing information about attacks
after they have finished. It seems to me that we are rapidly moving towards an automated future where Organizations are sharing information about attacks
while they are happening. This change is a subtle one, but one that has implications for STIX.

 

At present we have no way for an Organizations to temporarily ‘group’ different STIX objects together. When one is conducting an investigation
 into a series of suspicious events prompted by your Organization’s monitoring processes, we often want to tag/relate these events together, without actually creating an official ‘Incident’ (as we’re not sure anything has actually happened yet). The Incident
 object is where one would put the information when it is confirmed there is a problem, but I believe we at least need a way of ‘tagging’ and ‘grouping’ potentially related items together.

 

Does anyone else see the need for something like this?

 

Cheers

 

Terry MacDonald

Senior STIX Subject Matter Expert

SOLTRA | An FS-ISAC
 and DTCC Company

+61 (407) 203 206 |
 

 

 

From: Sarah Kelley [mailto:]

Sent: Tuesday, 27 October 2015 10:18 PM

To: Unknown Unknown <>; Jordan, Bret <>

Cc: Terry MacDonald <>; Baker, Jon <>; Jonathan Bush (DTCC) <>; Cory Casanave <>; 

Subject: Re: [cti-stix] Conceptul model for sighting

 

I am a huge proponent of letting (almost) anything link to anything. In fact, limiting what can have an association/link/relationship with what is my current biggest
 frustration with Stix (we use workarounds to get around this limitation). 

 

I would add the possible use cases:

 

My org observed 3 instances of this threat actor hitting our network

My org observed 12 instances of the Poison Ivy TTP on our network

Or even (though weaker):

My org was hit by this particular campaign 27 times

 

 

 

Sarah Kelley

Senior CERT Analyst

Center for Internet Security (CIS)

Integrated Intelligence Center (IIC)

Multi-State Information Sharing and Analysis Center (MS-ISAC)

1-866-787-4722 (7×24 SOC)

Email: 

www.cisecurity.org

Follow us @CISecurity
← Prev in month ← Prev in thread