Next in thread → Next in month →

Re: [cti-stix] Re: [cti] Proposal of confidence level using MISP taxonomies

From
Jason Keirstead <>
Date
2016-09-12T18:32:27+00:00
ID
Thread
Re: [cti-stix] Re: [cti] Proposal of confidence level using MISP taxonomies
I hate to channel my inner Rumsfeld, but there actually is a difference between an unknown value and a known unknown value.

If we declare that -1 is a valid value in the standard, then people should not be declaring it as an unsigned type. And in JSON, Number types are always signed so it's a non issue there...

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown 

Andras Iklody ---09/12/2016 02:54:27 PM----1 could get tricky if someone blindly inserts it using unsigned data types. Not setting a value if

From:        Andras Iklody <>
To:        Jason Keirstead/CanEast/IBM@IBMCA
Cc:        OASIS CTI TC Discussion List <>, , Alexandre Dulaunoy <>
Date:        09/12/2016 02:54 PM
Subject:        Re: [cti-stix] Re: [cti] Proposal of confidence level using MISP taxonomies

-1 could get tricky if someone blindly inserts it using unsigned data types. Not setting a value if it is unknown sounds a bit cleaner.

On Sep 12, 2016 7:09 PM, "Jason Keirstead" <> wrote:For the numerical value of "Confidence cannot be evaluated", could we use "-1" ?

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown 

Alexandre Dulaunoy ---09/12/2016 12:36:12 PM---Dear, Following the recent and good discussions at the TC, here is a proposal of confidence

From: Alexandre Dulaunoy <>
To: , OASIS CTI TC Discussion List <>
Date: 09/12/2016 12:36 PM
Subject: [cti] Proposal of confidence level using MISP taxonomies
Sent by: <>

Dear,

Following the recent and good discussions at the TC, here is a proposal of confidence
level that we will implement in MISP via the misp-taxonomies:

{
    "predicate": "confidence-level",
    "entry": [
       {
         "expanded": "Completely confident",
         "value": "completely-confident",
         "numerical_value": 100
       },
       {
         "expanded": "Usually confident",
         "value": "usually-confident",
         "numerical_value": 75
       },
       {
         "expanded": "Fairly confident",
         "value": "fairly-confident",
         "numerical_value": 50
       },
       {
         "expanded": "Rarely confident",
         "value": "rarely-confident",
         "numerical_value": 25
       },
       {
         "expanded": "Unconfident",
         "value": "unconfident",
         "numerical_value": 0
       },
       {
         "expanded": "Confidence cannot be evaluated",
         "value": "confidence-cannot-be-evalued"
       }
    ]
}

https://github.com/MISP/misp-taxonomies/blob/master/misp/machinetag.json#L31

Feedback welcome. I also included the original slides I gave during the TC in Brussels.

I'll summarize the various options of integration with the taxonomies in STIX in another email.

Cheers.

-- 
Alexandre Dulaunoy
CIRCL - Computer Incident Response Center Luxembourg
41, avenue de la gare L-1611 Luxembourg
 - www.circl.lu
[attachment "misp-OASIS-TC-Brussels-2016.pdf" deleted by Jason Keirstead/CanEast/IBM] 
---------------------------------------------------------------------
To unsubscribe from this mail list, you must leave the OASIS TC that 
generates this mail.  Follow this link to all your TCs in OASIS at:
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
Next in thread → Next in month →