Next in thread → Next in month →

RE: [cti-stix] Applying data markings

From
Marlon Taylor
Date
2015-12-11T19:51:00+00:00
ID
Thread
RE: [cti-stix] Applying data markings
Hi Jason,

Aligning with Pat’s reference to the TAXII spec and the fact the STIX documents are being shared via other mechanisms than TAXII brings more importance for  these cases to the addressed in the spec. (the over engineered statement)

Leaning towards the “holes”, you mentioned, we might be creating, I look at this as good things(extensibility) in the spec. CTI will not be able to provide  the processing rules for all possible markings placed on a document; However, given the spec, CTI can lay out the expected format(producer) and interpretation of that format(consumer) without going into the further processing (legal/business agreements) around  those markings.

-Marlon
From:
Jason Keirstead [mailto:]
Sent:  Friday, December 11, 2015 1:59 PM
To:  Patrick Maroney
Cc:  Aharon Chernin; ; Wunder, John A.; Taylor, Marlon; Barnum, Sean D.
Subject:  Re: [cti-stix] Applying data markings

Coming up with a specification for markings without any idea how said markings should be consumed or interpreted by the recipient, does not make sense to me. This has always been my gripe with TLP and STIX markings in general.
How will we know if we "get it right" with markings, if we are not starting from a baseline understanding of how a marking should be processed end to end? Without that baseline level of understanding there is not much purpose to the definition of markings...  we could be making a standard that has enormous holes in it, or we could be making one that is significantly over-engineered (I doubt it is the latter but could easily be the former)
-  Jason Keirstead  Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security
www.securityintelligence.com
Without data, all you are is just another person with an opinion - Unknown
Patrick  Maroney ---12/11/2015 02:46:57 PM---Jason, I see many discussions that seem to conflate and confuse a number of topics like "Data Markin
From:
Patrick Maroney < 
>
To:
Jason Keirstead/CanEast/IBM@IBMCA, "Wunder, John A." < 
>
Cc:
Aharon Chernin <  >, "  " <  >,  "'Taylor, Marlon'" <  >, "Barnum, Sean D." < 
>
Date:
12/11/2015 02:46 PM
Subject:
Re: [cti-stix] Applying data markings
Jason,
I
see many discussions that seem to conflate and confuse a number of topics like "Data Markings" as well.  A core tenet of the TAXII Standard has always been the following:
5.2.1 TAXII is Content Agnostic
T he TAXII specifications do not provide details about the underlying content formats of records within TAXII. All content formats are a "black-box"  as far as TAXII is concerned - none of the behaviors required to process TAXII at the message level require inspection of any information stored within message content.  While
TAXII Back-ends can have very different processing paths and requirements for different types of information  ,  TAXII Services, Messages, and Exchanges are agnostic as to the information they convey. This allows TAXII to be usable for a wide array of sharing scenarios.
Discussions around "Back-Ends" and STIX "Repositories" are very much implementation specific details from my perspective.
Patrick Maroney
Office: (856)983-0001
Cell: (609)841-5104

President
Integrated Networking Technologies, Inc.
PO Box 569
Marlton, NJ 08053
From:
<

>  on behalf of Jason Keirstead <

>
Date:  Friday, December 11, 2015 at 1:24 PM
To:  John Wunder <

>
Cc:  "Chernin, Aharon" <

>, "

"  <

>, Jason Keirstead <

>,  Marlon Taylor <

>, Sean Barnum <

>
Subject:  RE: [cti-stix] Applying data markings
There is something I still to this day don't grock about partial makings, especially the ill-defined "TLP". I feel like not enough thought is placed into how the consumer, specifically a TAXII  server, is supposed to implement support for the markings.
If I have a STIX document and it is marked in such a way that I can see 1/2 of that document but not the other, when that document is published to a TAXII channel that I am privy to, what do I receive as a consumer? Do I receive a partial document? Do I not  receive the document at all?
If it is the former, then what is the point of having Level 2 markings, and furthermore, how can we ensure the document is not incomplete (for example what if an Indicator I have access to has an observable reference that I do not)?
If it is the latter, how can that be done by the TAXII server without changing the digital signature of the document?
-  Jason Keirstead  Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security
www.securityintelligence.com
Without data, all you are is just another person with an opinion - Unknown
Next in thread → Next in month →