Just to give a little context around this question, this came up in a
conversation between Ali (well, several Soltra people) and myself today.
In our instance of Soltra Edge, we have (on many occasions) had to ‘edit’
an observable. Currently this involves editing the indicator, deleting the
link to the current Cybox observable, and creating a new observable. This
leaves lots of orphaned observables in our database that we really need to
have the ability to purge. The understanding we have is that currently
Cybox doesn’t support any sort of revoke/purge like Stix does.
Sarah Kelley
Senior CERT Analyst
Center for Internet Security (CIS)
Integrated Intelligence Center (IIC)
Multi-State Information Sharing and Analysis Center (MS-ISAC)
1-866-787-4722 (7×24 SOC)
Email:
www.cisecurity.org
Follow us @CISecurity
On 11/10/15, 11:06 AM, " on behalf of
Kirillov, Ivan A." < on behalf of
> wrote:
>Great question Ali; unfortunately I don’t have much insight into this
>topic. Moving this to the STIX list - I think revocation is more specific
>to STIX (though it clearly touches upon CybOX as well).
>
>Regards,
>Ivan
>
>
>
>
>On 11/10/15, 11:00 AM, " on behalf of
>Jerome Athias" < on behalf of
>> wrote:
>
>>Potential review of this
>>https://stixproject.github.io/data-model/1.2/indicator/ValidTimeType/
>>Suggestions welcome
>>
>>2015-11-10 18:48 GMT+03:00 Ali Khan <>:
>>> What is the cybox committees discussion so far for future versions to
>>> support ability to revoke and remove completely a cybox observable
>>>that was
>>> created and then shared but now there is a need to remove it.
>>>
>>>
>>>
>>>
>>>
>>> Thank You
>>>
>>>
>>>
>>> Ali Khan
>>> Lead Analyst
>>>
>>> SOLTRA | An FS-ISAC & DTCC Company
>>>
>>> Tampa, fl 33647
>>>
>>> 813.470.2197 |
>>>
>>>
>>>
>>>
>>
>>---------------------------------------------------------------------
>>To unsubscribe from this mail list, you must leave the OASIS TC that
>>generates this mail. Follow this link to all your TCs in OASIS at:
>>https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
>>
>
>...
This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
. . .