cti-stix — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
STIX 2.0 - Sightings object
I think a relationship object is about relating one object with multiple other objects but it does not really mean you have seen it. It just means you have done research on it and you think this thing is related to this other thing and that other thing .
A sighting object is a different kind of assertion, basically saying that the object has been seen. So something as simple as:
ID: Sighting GUID Marking_ID: The ID to a Marking structure. (optional)
Object_ID: The object that was seen Producer: The person that is claiming they saw it. Timestamp: Time stamp that it was seen
While a lot of the fields are similar, I feel like they are two different things. Playing devils advocate, one could argue that from the data model perspective, an indicator is really just a subset of fields from the incident object. So an indicator is just an incident with not all of the fields filled out... If you do not believe me, list out all of the fields side by side and see how they relate. Some of the fields are called different things, but the data they hold is the same.
From a sighting object standpoint I can see hundreds of millions of these messages flowing around on any given day. Relationship objects will be orders of magnitude less, IMO.
Thanks,
Bret
Bret Jordan CISSP
Director of Security Architecture and Standards
Office of the CTO Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg.
On Aug 20, 2015, at 09:58, Aharon Chernin < [email protected]
> wrote:
Bret, I almost always prefer atomic objects.
If we do both a relationship object and a Sightings atomic object together, it just seems... well weird.... (not very scientific I know)
Example Sightings Object -
ID: Sighting GUID
Marking: Sighting TLP
Producer: Who made the sighting
Timestamp:
?Target_ID: Replaced by Relationship Object
Now I am going to be forced to use the relationship object to make the Sighting work. I am also going to be forced to make a potentially large number of new Sighting Objects (since there is a timestamp). Also, a sighting by itself, without the looking into the Relationship object is kind of useless.
We can eliminate this extra complexity by eliminating the atomic Sightings object and replacing it with a relationship type.
Just debating <OutlookEmoji-
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]