Gary,
I personally think that is great. The other thing that I think is missing is a priority order to the elements in external_references.
Maybe you can open a Github issue and make a suggestion in the WD01 documents?
Bret
From: <> on behalf of Katz, Gary CTR DC3/TSD <>
Sent: Monday, July 23, 2018 8:07:36 AM
To:
Subject: [EXT] [cti-stix] External References
It seems I was sending these emails to the wrong distro, hopefully this works this time. Interested in everyone’s thoughts
-Gary
Currently we have a common data type attached to each object called ‘external-reference’. The STIX Core Concepts document only provides the following details
for how this property must be formatted.
“A non-STIX identifier or reference to other related external content.”
This can make it difficult for a system to understand what to do with the content within this field. I put together a short type definition to provide some
structure to this property. Please take a look and provide thoughts.
Thanks,
-Gary
https://clicktime.symantec.com/a/1/dDDDvemcgl9p5etO-Wtm3aEkCFoZS_zXuiK3xmeSTZw=?d=l55V5yJ2M4yxMkP99OQPwnlJcWvBbzpMBKn2GmFZ_oaysMqoMe4k5BmZ8LJUstIKAR1hy8F0rrCQf2MY7Tdl0DlXvuVOQOytqPRoUWc7donVyBekBkL2-rpRIUFafp8rPB-UaR-btWf_XAZo8Yp1pzWVi2wHsQ03VUjzFpdBNL0RBBXNSIXvfgkwkuDLyXdsUxrix25j78wFFk4zaHUftzBYSqu5o9-QcR5p_PxnvSO0lvMJBdXFrhNKFGsIyOLFnf0O6zDc7DKohzlBKUXfeSC-VVn4-jka6tFFfsPuJFl0vTwSrXbJr1YyKVRGBG12WaMMATpD160qu9DCpReAShKrfHLZjC4O_PS19cH7pwx5lmlVTUmumVANa0izwhfBSw57R7mXzruLX0HDMcaYG117RqbrxEv_YQ51jkP5UbUfvrRbiw%3D%3D&u=https%3A%2F%2Fdocs.google.com%2Fdocument%2Fd%2F1SlCPTlGCM6QPehd3m_tGz_O6USZ7NiZLoGULwJeU33o%2Fedit%3Fusp%3Dsharing