OASIS Open Mailing List Archives  ·  All Lists  ·  cti-stix  ·  2015-07

cti-stix — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Proposal - Change Report Object


I have a call with Sean later today. We will discuss and post back to the list. Aharon Chernin CTO SOLTRA An FS-ISAC & DTCC Company 18301 Bermuda green Dr Tampa, fl 33647 813.470.2173 [email protected] www.soltra.com From: Wunder, John A. <[email protected]> Sent: Monday, July 27, 2015 12:40 PM To: Jordan, Bret; Aharon Chernin Cc: Jason Keirstead; Trey Darley; [email protected] Subject: Re: [cti-stix] Proposal - Change Report Object FWIW this would potentially be overcome by the top-level relationship construct. Though, for things like indicator composition and the observable within an indicator you would probably not use that construct. Aharon and Sean, how do you want to handle these types of discussions to work towards a decision? I know on the MITRE lists we would have these discussions and they would sometimes kind of peter out without a solid consensus. Any thoughts on how to avoid that here? John From: "Jordan, Bret" Date: Monday, July 27, 2015 at 12:33 PM To: Aharon Chernin Cc: "Wunder, John A.", Jason Keirstead, Trey Darley, " [email protected] " Subject: Re: [cti-stix] Proposal - Change Report Object Agreed..  We need to talk through this and think about it.  We need to weigh the value of it and its complexity and impossibility to implement, versus something much easier to understand and easier to implement.   Some of the existing constructs in STIX I think need to be dropped and replaced in whole with something easier to understand and use. Composite indicators might be one of those case, but I have not spent enough time thinking about them yet.  Too focused on other areas that are hemorrhaging. Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." On Jul 27, 2015, at 10:28, Aharon Chernin < [email protected] > wrote: In general, I favor referencing over inline. The only thing I haven't put much thought on is how I feel about requiring referencing when doing something like composite indicators. Aharon Chernin CTO SOLTRA An FS-ISAC & DTCC Company 18301 Bermuda green Dr Tampa, fl 33647 813.470.2173 [email protected] www.soltra.com From: [email protected] < [email protected] > on behalf of Jordan, Bret < [email protected] > Sent: Monday, July 27, 2015 12:19 PM To: Wunder, John A. Cc: Jason Keirstead; Trey Darley; [email protected] Subject: Re: [cti-stix] Proposal - Change Report Object I could go with that... Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." On Jul 27, 2015, at 10:07, Wunder, John A. < [email protected] > wrote: I'm going to throw out there that we should make ALL relationships between top-level constructs reference only. That would include Report, but also things like TTPs in Indicators, etc. From: < [email protected] > on behalf of Jason Keirstead Date: Monday, July 27, 2015 at 11:59 AM To: Trey Darley Cc: "Jordan, Bret", " [email protected] " Subject: Re: [cti-stix] Re: Proposal - Change Report Object I also +1 this if we are counting votes. - Jason Keirstead Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security www.securityintelligence.com Without data, all you are is just another person with an opinion - Unknown <graycol.gif> Trey Darley ---2015/07/27 12:13:59 PM---+100, Bret! Cheers, From: Trey Darley < [email protected] > To: "Jordan, Bret" < [email protected] >, " [email protected] " < [email protected] > Date: 2015/07/27 12:13 PM Subject: [cti-stix] Re: Proposal - Change Report Object Sent by: < [email protected] > +100, Bret! Cheers, Trey -- Trey Darley Senior Security Engineer Soltra An FS-ISAC & DTCC Company www.soltra.com From: [email protected] < [email protected] > on behalf of Jordan, Bret < [email protected] > Sent: Monday, July 27, 2015 16:57 To: [email protected] Subject: [cti-stix] Proposal - Change Report Object In STIX 2.0 I would like to propose that we change the Report Object to contain just reference to the objects that it is binding. I do not want to see it contain data itself. [soap box] We need one way of doing things and the current data-model of STIX, while beautiful, makes writing a decision tree in code for some arbitrary data in a STIX package nearly impossible. . [/soap box] Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." <graycol.gif>

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]