← Prev in month ← Prev in thread

Ideas for TAXII 2.0

From
Bret Jordan
Date
2015-08-15T00:25:00+00:00
ID
Thread
Ideas for TAXII 2.0
All,
I have been thinking through the ideas that we have presented thus far, that seems to be accepted by everyone, and have started drawing connection point to what that would mean if we were to move forward. To this end I have also started writing a prototype implementation, a  nominal  implementation, that would make use of these concepts. The reason for this is, I find it hard to fully understand requirements and problems until you start putting ideas to code as some really good ideas do not work in code and I would like to flush them out early.
Now if,
and I stress IF  , we continue to move down this path, here are some process flow diagrams that might make it easier for people to understand what we are talking about..
These diagrams represent a TAXII 2.0 channel system over HTTP with long polling, one of the proposed options.  This does
NOT
mean, this is what we are going to do, but rather, if we continue down this path and happened to choose HTTP long polling, then this is what we would be looking at.
As always, this is designed to foster communication and get people thinking and talking about these ideas in more detail.
Assertions:
TAXII 2.0 uses channels  We have segmentation via Groups  Every TAXII server has a default group with defined channels  Extension points for additional groups where each new group would be required to have at least the defined channels  Extension points for additional channels on any group
This first diagram show a client connecting to a TAXII server and what that would mean to process the connection request
Attachment:
process1.pdf
Description:  Adobe PDF document
This second diagram deals with processing of messages that come in to a channel on a TAXII server.
Attachment:
process2.pdf
Description:  Adobe PDF document
Thanks,
Bret
Bret Jordan CISSP
Director of Security Architecture and Standards
Office of the CTO  Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.
Attachment:
signature.asc
Description:  Message signed with OpenPGP using GPGMail
← Prev in month ← Prev in thread