OASIS Open Mailing List Archives  ·  All Lists  ·  cacao  ·  2019-09

cacao — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

How best to do multiple actions


+1 Having two abstract layers, one for the actions and one for logic would allow to reuse the actions (in a more appropriate manner/better engineering). I can imagine that I have a bucket that is filled with actions that I can re-use. This can also support the use of playbooks in deriving extra intelligence and insights. Just a thought, for example in terms of CTI,  we can map and visualise playbooks in respect to common actions related to IoCs easily and why not having a similarity index that can show overlap percentage among playbooks. Ill try to engineer a schema for the second approach starting next week. If somebody wants to help please let me know. Best, Vasileios Mavroeidis  Security Researcher and Ph.D. Research Fellow Research Group of Information and Cyber Security (SECURITY) SecurityLab University of Oslo On 18 Sep 2019, at 19:24, Ghosh, Anup A. < [email protected] > wrote: Hi Bret, I think this is a useful discussion to get us thinking about these details. I like the second approach for the following reasons: it lists the atomic actions which can be considered building blocks to a play. The play then is able to add (temporal) logic to the building blocks to meet both the end objective of the play as well as capture the dependencies. Different plays will have different logic and dependencies which allows us to re-use the building blocks rather than starting from scratch each time. Thanks! Anup

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]