Re: [cti-stix] STIX 2.0 Architecture - Relationships, Sightings, and Targeting

From
Patrick Maroney <>
Date
2015-10-28T13:39:20+00:00
ID
Thread
Re: [cti-stix] STIX 2.0 Architecture - Relationships, Sightings, and Targeting
In our World View and a majority of Use Cases, one needs to fully model all aspects of the Cyber-BattleSpace:

Adversaries

Adversary TTP*s (Black Hat)

Intermediaries 

Intermediary TTPs (Grey Hat)

Targets

Target TTPs (White Hat)

* TTPs include assets and infrastructure in this model.

Since we don't currently represent Targets and Intermediaries in the current CTI Model, then the proposed modeling of related "White/Grey Hat" TTP relations won't be as obvious

Patrick Maroney

From: Jerome Athias <>

Date: Wednesday, October 28, 2015 at 5:22 AM

To: Trey Darley <>

Cc: Patrick Maroney <>, Anthony Rutkowski <>, Mark Davidson <>,
 "" <>

Subject: Re: [cti-stix] STIX 2.0 Architecture - Relationships, Sightings, and Targeting

I guess so (Blue/Red teams), only covered, I would say by the 'exercise' flag but not in the vocabularies

On Wednesday, 28 October 2015, Trey Darley <> wrote:

On 26.10.2015 17:16:02, Patrick Maroney wrote:

>

> ...including the missing concepts of White Hat TTPs...

>

Hey, Pat -

When you say, 'White Hat TTPs', do you mean sharing intelligence

useful in identifying legitimate pen-tester activity?

--

Cheers,

Trey

--

Trey Darley

Senior Security Engineer

4DAA 0A88 34BC 27C9 FD2B  A97E D3C6 5C74 0FB7 E430

Soltra | An FS-ISAC & DTCC Company

www.soltra.com

--

"Every networking problem always takes longer to solve than it seems

like it should." --RFC 1925