OASIS Open Mailing List Archives  ·  All Lists  ·  cti-taxii  ·  2015-10

cti-taxii — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

The need (or no need) for TAXII to support Query


Hi All, Just splitting this out into its own thread so we can all keep track :) I half agree with Jason :). I think Query is outside of the scope of TAXII, but I also think it is the responsbility of each carried protocol to provide its own query and response functionality if it requires it. To me TAXII has the express purpose of enabling the sharing of CTI data (over a channel). To me that means that TAXII is only worried about: - ensuring everyone allowed to see the CTI data channel sees it - allowing people to request access to the CTI data channel - allowing channel owners to allow access to the CTI data channel TAXII should effectively treat the information carried within TAXII as a 'black box' from the TAXII perspective. As an example, if a TAXII channel is carrying STIX data, then it should be the responsibility of STIX to ask queries for STIX data. Similarly, if in the future TAXII carries VERIS classification data, then it should be the responsibility of VERIS to ask queries for VERIS data. TAXII should just ensure that the data gets to where it should go, and that only those who are allowed to see it, receive it. (And that it is marked to contain either STIX or VERIS data so the receiving TAXII process knows which process to hand the carried data to. Loosely coupling TAXII from the data it carries gives us future flexibility for what TAXII can carry. Tightly coupling TAXII by enforcing support for STIX querying restricts this flexibility, and ensures that when new version of STIX is released we will need to release a new version of TAXII query to support it. And then restricts the ability for us to add new protocols to be carried by TAXII (e.g. VERIS) as new TAXII query releases would be required there too. Cheers Terry MacDonald STIX, TAXII, CybOX Consultant M: +61-407-203-026 E:  [email protected] W:  www.threatloop.com Disclaimer: The opinions expressed within this email do not represent the sentiment of any other party except my own. My opinions do not necessarily reflect those of Threatloop.com. On 17 October 2015 at 01:57, Jason Keirstead < [email protected] > wrote: From my perspective - while I think that having QUERY for CTI is a fundamental and necessary use case - I think bundling it in with TAXII creates needless confusion. Not all use cases for TAXII care about QUERY. And not all use cases that care about QUERY, care about TAXII. QUERY also has a lot more implicit ties to the data model. TAXII does not need any of these. I feel that QUERY should be it's own separate API that may even follow a totally different paradigm. It should have it's own, seperate specification - and if needed, even have a different CTI subcommittee created for it. It's really an entirely different use case. Just because they were shoe-horned together in TAXII 1.X does not mean we can not fork it off now. - Jason Keirstead Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security www.securityintelligence.com Without data, all you are is just another person with an opinion - Unknown "Davidson II, Mark S" ---2015/10/16 08:37:12 AM---Trey, One of our stated requirements for TAXII 2 is feature parity with TAXII 1.x [1]. To me, that m From: "Davidson II, Mark S" < [email protected] > To: Trey Darley < [email protected] >, "Jordan, Bret" < [email protected] > Cc: " [email protected] " < [email protected] > Date: 2015/10/16 08:37 AM Subject: RE: [cti-taxii] Items in scope vs out of scope Sent by: < [email protected] > Trey, One of our stated requirements for TAXII 2 is feature parity with TAXII 1.x [1]. To me, that means query has not been scoped out. That said, there is still plenty of conversation to be had about query (e.g., what feature set constitutes 'feature parity' as well as the actual design). The graphic Bret shared was intended to convey that for any particular discussion there are four high level buckets of "scope" to consider. The graphic was not intended to be a complete list of TAXII 2 features - it only includes items that this SC have discussed so far. If you (or anyone) have ideas or requirements for query, please share them! Thank you. -Mark [1] https://github.com/TAXIIProject/TAXII-Specifications/wiki/TAXII-2.0-Requirements

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]