Re: [cti] CybOX Datatype Refactoring/Deprecation

From
Jason Keirstead <>
Date
2016-03-22T14:55:20+00:00
ID
Thread
Re: [cti] CybOX Datatype Refactoring/Deprecation
I understand the encoding one, but not the obfuscated one. If someone wants to obfuscate (either reversibly or irreversibly) an email or URL before publishing it, we can't prevent that. I am not sure what is meant by "support" in this case. 
-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown 

"Kirillov, Ivan A." ---03/22/2016 11:29:07 AM---Now that we’ve voted to not support defanging, the question remains as to whether we should support

From:        "Kirillov, Ivan A." <>
To:        "''" <>
Date:        03/22/2016 11:29 AM
Subject:        Re: [cti] CybOX Datatype Refactoring/Deprecation
Sent by:        <>

Now that we’ve voted to not support defanging, the question remains as to whether we should support obfuscation and capture of observed encoding on CybOX Object fields:
Obfuscation example:  or . Also used for URLs. 
Observed encoding: utf-8, etc. Mostly relevant for malware analysis and attribution, e.g., if an actor is known to use a particular encoding in their comment strings.
Regards,
Ivan