OASIS Open Mailing List Archives  ·  All Lists  ·  cti-stix  ·  2015-07

cti-stix — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Proposal - Top Level Relationship Object


I suggested Github before, but now I am starting to think that all the SCs should use the same method for tracking issues. Deciding this common method should not be done through the STIX SC alone, the SC chairs should get together to discuss a common way of doing this. Aharon Chernin CTO SOLTRA An FS-ISAC & DTCC Company 18301 Bermuda green Dr Tampa, fl 33647 813.470.2173 [email protected] www.soltra.com From: [email protected] <[email protected]> on behalf of JG on CTI-TC <[email protected]> Sent: Wednesday, July 29, 2015 2:12 PM To: [email protected] Subject: Re: [cti-stix] Proposal - Top Level Relationship Object Sean/Aharon: So, should something like this...that is something that has been hashed out through an eMail / ListServe conversation be added to the STIX Wiki on OASIS?  I'm trying to get a sense of how issues like this are going to be memorialized.  I saw some conversations about continuing issue tracking on GitHub.  Will the STIX Sub-Committee being doing that on GitHub or tracking issues on the OASIS STIX Wiki? I'm just tying to get a sense of where to look if I need to go back and reconstruct the results of this conversation. Jane Ginn On 7/29/2015 11:04 AM, Jordan, Bret wrote: So based on everyones comments thus far, I am summarizing to: ID  [1] [Required]: The ID of the relationship Version  [1] [Required]: The version of the relationship; a simple number to be used with the ID for version control (instead of timestamp) Type  [1] [Required]: The “type” of relationship being expressed.  (Not sure of how this works yet) Description  [0..N] [Optional]: Words about the relationship. Objects   [2..N] [Required]: The ID of one or more targets in the relationship as a URI (not QName) Start_Time  [0..1] [Required]: A timestamp in UTC stating when the relationship between the objects started, or the text 'unknown'. End_Time  [0..1] [Required]: A timestamp in UTC stating when the relationship between the objects ended, or the text 'ongoing', or the text 'unknown'. Confidence  [1] [Required]: A measure of confidence in the relationship. Timestamp  [0..1] [Required]: A timestamp in UTC stating when the relationship object was created. Source   [0..N] [Optional]: A URL pointing to source of the information that allowed the relationship to be created (not the producer as that is inherently in the ID's). Thanks, Bret Bret Jordan CISSP Director of Security Architecture and Standards Office of the CTO Blue Coat Systems PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." -- Jane Ginn, MSIA, MRP Cyber Threat Intelligence Network, Inc. [email protected]

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]