Re: [cti-stix] How should this look

From
Sean Barnum
Date
2016-01-29T15:10:00+00:00
ID
Thread
Re: [cti-stix] How should this look
This jibes with how I have been envisioning it.

  sean
From:  "  " < 
> on behalf of "Jordan, Bret" < 
>
Date:  Thursday, January 28, 2016 at 6:13 PM
To:  "  " < 
>
Subject:  [cti-stix] How should this look

  I want to start writing some APIs for STIX 2.0..  But I am not yet sure how things should look at the top level...  I am thinking something like????  This is meant to get people talking so we can start fleshing this out as cleanly and rapidly
  as possible.

 {

   "type": "stix-package",

   "id": "stix-package--ad3d029f-6fe7-4923-aafc-3b69aed32365",

   "indicators": [

     {

       "type": "indicator",

       "id": "indicator--3d5338a0-9305-4373-b59c-616ac2e9b18f",

       "timestamp": "2016-01-28T15:44:53Z",

       "title": "Some really neat indicator that we found"

     }

   ]

 }

  Thanks,

  Bret

Bret Jordan CISSP

 Director of Security Architecture and Standards
Office of the CTO

 Blue Coat Systems

  PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
  "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."