Re: [cti-stix] Malware SDO Remaining Open Questions

From
Trey Darley <>
Date
2017-10-27T18:26:39+00:00
ID
Thread
Re: [cti-stix] Malware SDO Remaining Open Questions
On 27.10.2017 16:43:32, Kirillov, Ivan A. wrote:
> My own thoughts:
> 
> 1. I feel like name should be flexible – we already have the samples
>    property for capturing the information about the binaries
>    associated with the malware, including their filenames.
> 
> 2. “Exploits” is much clearer and preferable than “targets” with
> regards to vulnerabilities (I’ve never seen any malware reporting
> which states that malware “targets” a vulnerability) so it’s worth
> making a breaking change for this.
> 

I concur entirely with Ivan's perspective.

-- 
Cheers,
Trey
++--------------------------------------------------------------------------++
Director of Standards Development, New Context
gpg fingerprint: 3918 9D7E 50F5 088F 823F  018A 831A 270A 6C4F C338
++--------------------------------------------------------------------------++
--
"In theory there is no difference between theory and practice; in
practice there is." --anonymous