And this is case in point of why I think you would be a great Co-Chair or Chair if Eric can not do it, for this work.
Thanks,
Bret
Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
On Jun 19, 2015, at 12:42, Jerome Athias <> wrote:
The users have basically an issue managing and sharing informationbecause this information is stored in various ways andrepresentations. (because of different and non-interoperablesoftwares)A common language was needed. (just like we use English there, becausewe don't all speak Chinese, Spanish, French or Russian, etc.)While we want humans to share information between each other, by usingmachines, these humans (users) need a way* to talk to machines(computers).If this language is seen/perceived as too complex (complicated, largeor 'grammatically' difficult to learn before being able to make "validsentences with the available words and rules of the language") by theusers; we need to assist them*.(Computer programming is there to assist.)More than just a "database subcommittee", this subcommittee couldsupport Software engineering.https://en.wikipedia.org/wiki/Software_engineeringRelational databases represent, IMHO, a significantly interesting ideato be explored to support and potentially enhance-extend the currentspecifications, and facilitate understanding and Software developmentaround and using the STIX family of domain-specific languages (DSL).I think that relational database schemas based and designed on thedata format specifications -could- facilitate the use of 4GLs tools inorder to build or generate easily (faster) Graphical User Interfaces*intended to greatly simplify the 'complexity' of the OASIS-CTIlanguages.Being a mature development approach (explored for decades) this couldprovide benefits such like a larger pool of skilled and availableresources (developers).PS: Furthermore, the possible resultant application programminginterfaces (APIs), could be used for M2M communications too.2015-06-19 19:50 GMT+03:00 Jordan, Bret <>:Great points..Thanks,BretBret Jordan CISSPDirector of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303"Without cryptography vihv vivc ce xhrnrw, however, the only thing that cannot be unscrambled is an egg."On Jun 19, 2015, at 10:43, Alex Pinto <> wrote:Ok, I think I get it now. By focusing on the “database” part of it, I becamea bit confused. Since the standards describe a data definition format, thetrivial and obvious solution would be to translate that to a relationaldatabase verbatim. I am glad I am not an investor on these startups that arestruggling to do something like that. ;)However, the larger implementation problem is a good one to address, in myopinion. What I have seen people struggling with is how to efficientlytranslate the data they have INTO the STIX data format. Say I have an IPaddress indicator from the “Tap-dancing Penguin” threat actor. what is thecorrect, unambiguous path, to translate that to the equivalent STIX object.Do I need to create an Observable? Only an Indicator? Can Threat Actors belinked directly to Indicators or do you need to have a Observable to dothat?However, I STILL think that having something along the lines of these“suggested recipes” of normal use-cases should be a part of eachsubcommittee. Because if there is more than one way to generate the the samepiece of information on the STIX format, we would have failed to describe anactual interoperable standard.Don’t get me wrong. I LOVE this idea of making it more developer-friendly,but I want to make sure we are focusing on the right things here.Cheers,Alex--Alex PintoNiddelhttp://niddel.comhttps://mlsecproject.orgOn Jun 19, 2015, at 6:26 PM, Jordan, Bret <> wrote:The subcommittee would create work products, documentation, and bestpractices for using STIX, TAXII and CYBOX. As I talk with start-ups andother implementors / integrators, I hear a common theme. "How do weactually store this data and what is the best practices for doing so?".This working group, in my mind, would address those issues and report backto the TC with recommend best practices, examples, and documentation on howto build the databases to actually make use of STIX, TAXII, and CYBOX.You could even put in scope the query functions that should exist for eachlanguage and how best to do those. It would be nice to have a working groupfocused on this effort. And IMHO, I think this would help get a lot ofnew people to STIX and TAXII up and running more quickly.Thanks,BretBret Jordan CISSPDirector of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303"Without cryptography vihv vivc ce xhrnrw, however, the only thing that cannot be unscrambled is an egg."On Jun 19, 2015, at 08:55, wrote:I need some more time to structure a more complete response right now(trying to catch flights out of Berlin) but I am really struggling tounderstand how can this possible be on the scope of the standard.Could you please elaborate how the actual database format would be relevantfor the standard discussion?On Fri, Jun 19, 2015 at 4:28 PM, Jordan, Bret <>wrote:And I would nominate Jerome to Co-Chair this with Eric Burger.Thanks,BretBret Jordan CISSPDirector of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303"Without cryptography vihv vivc ce xhrnrw, however, the only thing that cannot be unscrambled is an egg."On Jun 19, 2015, at 02:14, Jerome Athias <> wrote:+12015-06-19 6:11 GMT+03:00 Jordan, Bret <>:About 9 months ago or so we tossed around the idea of setting up aSubcommittee / Working group to look in to database requirements and buildphoto-type examples for storying STIX and or TAXII data. I would like topropose that we do that here at OASIS and I would nominate Eric Burger toChair this committee. He is after all a professor of computer science thatteaches database theory... I think we would be very lucky to have him runthis group.Thanks,BretBret Jordan CISSPDirector of Security Architecture and Standards | Office of the CTOBlue Coat SystemsPGP Fingerprint: 62A6 5999 0F7D 0D61 4C66 D59C 2DB5 111D 63BC A303"Without cryptography vihv vivc ce xhrnrw, however, the only thing that cannot be unscrambled is an egg."<signature.asc>This e-mail message and any files transmitted with it contain legallyprivileged, proprietary information, and/or confidential information,therefore, the recipient is hereby notified that any unauthorizeddissemination, distribution or copying is strictly prohibited. If you havereceived this e-mail message inappropriately or accidentally, please notifythe sender and delete it from your computer immediately.--------------------------------This e-mail message and any files transmitted with it contain legallyprivileged, proprietary information, and/or confidential information,therefore, the recipient is hereby notified that any unauthorizeddissemination, distribution or copying is strictly prohibited. If you havereceived this e-mail message inappropriately or accidentally, please notifythe sender and delete it from your computer immediately.<signature.asc>
Attachment:
signature.asc
Description: Message signed with OpenPGP using GPGMail