cti-stix — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
STIX 2.0 - Sightings object
That’s an interesting way of thinking about the relationship object. Seems to make sense to me.
From:
[email protected] [mailto:[email protected]]
On Behalf Of Jordan, Bret
Sent: Thursday, August 20, 2015 12:24 PM
To: Aharon Chernin
Cc: Davidson II, Mark S; [email protected]
Subject: Re: [cti-stix] STIX 2.0 - Sightings object
I think a relationship object is about relating one object with multiple other objects but it does not really mean you have seen it. It just means you have done research on it and you think this "thing" is related to this other "thing"
and that other "thing".
A sighting object is a different kind of assertion, basically saying that the object has been seen. So something as simple as:
ID:
Sighting GUID
Marking_ID:
The ID to a Marking structure. (optional)
Object_ID:
The object that was seen
Producer:
The person that is claiming they saw it.
Timestamp:
Time stamp that it was seen
While a lot of the fields are similar, I feel like they are two different things. Playing devils advocate, one could argue that from the data model perspective, an indicator is really just a subset of fields from the incident object. So
an indicator is just an incident with not all of the fields filled out... If you do not believe me, list out all of the fields side by side and see how they relate. Some of the fields are called different things, but the data they hold is the same.
From a sighting object standpoint I can see hundreds of millions of these messages flowing around on any given day. Relationship objects will be orders of magnitude less, IMO.
Thanks,
Bret
Bret Jordan CISSP
Director of Security Architecture and Standards
Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
On Aug 20, 2015, at 09:58, Aharon Chernin < [email protected]
> wrote:
Bret, I almost always prefer atomic objects.
If we do both a relationship object and a Sightings atomic object together, it just seems... well weird.... (not very scientific I know)
Example Sightings Object -
ID: Sighting GUID
Marking: Sighting TLP
Producer: Who made the sighting
Timestamp:
?Target_ID: Replaced by Relationship Object
Now I am going to be forced to use the relationship object to make the Sighting work. I am also going to be forced to make a potentially large number of new Sighting
Objects (since there is a timestamp). Also, a sighting by itself, without the looking into the Relationship object is kind of useless.
We can eliminate this extra complexity by eliminating the atomic Sightings object and replacing it with a relationship type.
Just debating <OutlookEmoji-
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]