← Prev in month ← Prev in thread
Next in thread → Next in month →

Changes to section 4.6 - Indicator

From
Piazza, Rich <>
Date
2019-11-13T21:15:28+00:00
ID
Thread
Changes to section 4.6 - Indicator
The editors changed the text, related to the pattern property of the Indicator, to address concerns discussed in emails and working calls.

 

Please review this new text and respond if you have additional concerns.

 

            Rich

 

pattern (required)

string

The detection pattern for this Indicator
MAY be expressed as a STIX Pattern as specified in section
 9 or another appropriate language such as SNORT, YARA, etc. 

pattern_type (required)

open-vocab

The pattern language used in this indicator. 

 

The value for this property
SHOULD come from the pattern-type-ov open vocabulary.. 

 

The value of this property
MUST match the type of pattern data included in the pattern property.

pattern_version (optional)

string

The version of the pattern language that is used for the data in the
pattern property which
MUST match the type of pattern data included in the pattern property. 

 

For patterns that do not have a formal specification, the build or code version that the pattern is known to work with
SHOULD be used.

 

For the STIX Pattern language the default value is inferred from the specification version of the object. 

 

For other languages, the default value
SHOULD be the latest version of the patterning language at the time of this object's creation.
← Prev in month ← Prev in thread
Next in thread → Next in month →