Re: [cti-stix] Timestamps - Proposal

From
Terry MacDonald <>
Date
2015-12-01T21:27:00+00:00
ID
Thread
Re: [cti-stix] Timestamps - Proposal
Note that in the effort to drive this to closure, "TimeStamps" have been discussed extensively in 3 contexts:  (1) TAXII, (2) _expression_ of "When" something occurred,
  and (3) _expression_ of intervals in patterns.

So in support of the "One Way of Doing Things" philosophy, and in the interests of driving to closure, it  would be useful to clarify which contexts the current
  decision applies to.



I assume that TAXII and the STIX when will align with the same definition for the (1) and (2) items described above.



I also believe that there is a need for a separate time_period/interval definition required as well…. But maybe we can just add it
  to the issues list for later discussion?



Terry MacDonald

Senior STIX Subject Matter Expert

SOLTRA
   An FS-ISAC and DTCC Company

+61 (407) 203 206


From:
 [mailto:]
  On Behalf Of  Patrick Maroney
  Sent:  Wednesday, 2 December 2015 7:35 AM
To:  Jordan, Bret <>
Cc:  
Subject:  Re: [cti-stix] Timestamps - Proposal



Much depends on the answer to (2), but I will give you your requested Use Case requirement for Millisecond precision: many common used Time/Date Utility libraries
  only support Milliseconds vs. full RFC compliant forms (   "time-secfrac = "." 1*DIGIT")  .



This was discussed in our original extended discussions on Time Representation on the original Lists if you need specific references to accept the assertion.



http://making-security-measurable.1364806.n2.nabble.com/template/NamlServlet.jtp?macro=search_page&node=1364806&query=%22time-secfrac%22&i=12



Note that in the effort to drive this to closure, "TimeStamps" have been discussed extensively in 3 contexts:  (1) TAXII, (2) _expression_ of "When" something occurred,
  and (3) _expression_ of intervals in patterns.

So in support of the "One Way of Doing Things" philosophy, and in the interests of driving to closure, it  would be useful to clarify which contexts the current
  decision applies to.



Patrick Maroney

Office:  (856)983-0001
Cell:      (609)841-5104

President

Integrated Networking Technologies, Inc.

PO Box 569
Marlton, NJ 08053
From:

Bret Jordan <

>
Date:  Tuesday, December 1, 2015 at 3:07 PM
To:  Patrick Maroney <

>
Cc:  "

" <

>
Subject:  Re: [cti-stix] Timestamps - Proposal



Good questions....  For (2) I would hope that where relevant STIX will support multiple time stamps to accomplish this need.  But at the current rate, that will
  probably be 9 months of debate... :(



For (3), it is always easier to add stuff than take stuff away.  And the group kind of felt like you either know to the microsecond or not.  Now some 10Gig/40Gig/100Gig
  networks will have support for nano second, but there did not seem to be any solid use-cases for mili second precision.  If I am wrong, PLEASE speak up.



We need to drive this to consensus.  We need to show that we can decide something...  So if you think we need milliseconds, and there are a broad range of tools
  that only support 3 sub-digit seconds, then please speak up.



From my standpoint, I really do not see the value in precision.  Or I should say, I only see value to a "day" and to greater than an "hour".  Anything outside of
  those windows is basically useless from an actionable stand point.  But I am coming to middle ground in order to get something done in STIX.



Thanks,



Bret







Bret Jordan CISSP

Director of Security Architecture and Standards
Office of the CTO

Blue Coat Systems

PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050

"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."



On Dec 1, 2015, at 12:57, Patrick Maroney <

>
  wrote:



Bret,



Presume you will be collecting, coordinating and documenting these so I'll respond directly to your initial message vs. jumping into the the Thread:





2) Timestamps MUST use the timezone offset



Question:  Does this mean there will be another Time Specification for _expression_ of relative time, periodicity and intervals?



4) There will be an optional precision field (timestamp-precision) with the following string values: year, month, day, hour, minute, second. If precision is omitted,
  the default value of precision is "microsecond"



Question:  Since extending beyond RFC 3339, why can't this option precision type enumeration include millisecond, microsecond, and nanosecond?



Patrick Maroney

Office:  (856)983-0001
Cell:      (609)841-5104



<C690F973-64C5-4C00-889B-C1A5BB4A2A0B[13].png>



President

Integrated Networking Technologies, Inc.

PO Box 569
Marlton, NJ 08053