OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-cybox] CybOX 3.0: File Object Refactoring


Me to come back tomorrow with the RFC ID and quote, but in short: we should not try to cover all use cases while sub-classing is fine if possible 

On Tuesday, 15 December 2015, Jason Keirstead <Jason.Keirstead@ca.ibm.com> wrote:

I tend to agree.. I am trying to figure out who is setting "is masqueraded" and under what circumstances and what the use case is for this field.

Say I use stenography to encode an executable inside of an image. Is that a "masqueraded" file that should not have a image/png mime type? It is actually a valid image. I argue that is the correct mime type, because *that* is the indicator.

Say I embed an executable into a word document using built in features. Is that a "masqueraded" file that should have a mime type of word? Again, it is a valid word document and IMO it is still an indicator. You do not want to lose the fact that it is a word document.


-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Kirillov, Ivan A." ---12/15/2015 12:52:48 PM---I think “is_packed” will likely be included in the "Kirillov, Ivan A." ---12/15/2015 12:52:48 PM---I think “is_packed” will likely be included in the next release, perhaps as part of the metadata ext

From: "Kirillov, Ivan A." <ikirillov@mitre.org>
To: "Wunder, John A." <jwunder@mitre.org>, Jerome Athias <athiasjerome@gmail.com>
Cc: Patrick Maroney <Pmaroney@specere.org>, Jason Keirstead/CanEast/IBM@IBMCA, "Barnum, Sean D." <sbarnum@mitre.org>, "John Anderson" <janderson@soltra.com>, Paul Patrick <ppatrick@isightpartners.com>, "Jordan, Bret" <bret.jordan@bluecoat.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>, Terry MacDonald <terry@soltra.com>
Date: 12/15/2015 12:52 PM
Subject: Re: [cti-cybox] CybOX 3.0: File Object Refactoring
Sent by: <cti-cybox@lists.oasis-open.org>





I think “is_packed” will likely be included in the next release, perhaps as part of the metadata extension.

I’m on the fence as far as explicitly capturing that a file is masqueraded – as John pointed out below, this can already be done implicitly by capturing the file name/extension and MIME type. If the two do not match, then it is likely a case of masquerading.

I know that we have this property in the existing File Object, but I’ve always considered it a product of analysis rather than pure observation. IMO, we should leave analytical findings to other places where they make more sense (probably STIX), and leave CybOX to “just the facts”.

Regards,
Ivan

From: John Wunder <jwunder@mitre.org>
Date:
Tuesday, December 15, 2015 at 9:48 AM
To:
Jerome Athias <athiasjerome@gmail.com>
Cc:
Patrick Maroney <Pmaroney@specere.org>, Jason Keirstead <Jason.Keirstead@ca.ibm.com>, Sean Barnum <sbarnum@mitre.org>, Ivan Kirillov <ikirillov@mitre.org>, John Anderson <janderson@soltra.com>, Paul Patrick <ppatrick@isightpartners.com>, Bret Jordan <bret.jordan@bluecoat.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>, Terry MacDonald <terry@soltra.com>
Subject:
Re: [cti-cybox] CybOX 3.0: File Object Refactoring

Yep, that’s one mechanism. Are there others?

I’m just suggesting that we should be precise and encode these specific mechanisms rather than some generic field. In the case of a mis-named file, I think we’re all set (the content type will not match the extension in the file name) so maybe there’s nothing to add.

From: Jerome Athias <athiasjerome@gmail.com>
Date:
Tuesday, December 15, 2015 at 11:44 AM
To:
"Wunder, John A." <jwunder@mitre.org>
Cc:
Patrick Maroney <Pmaroney@specere.org>, Jason Keirstead <Jason.Keirstead@ca.ibm.com>, Sean Barnum <sbarnum@mitre.org>, Ivan Kirillov <ikirillov@mitre.org>, John Anderson <janderson@soltra.com>, Paul Patrick <ppatrick@isightpartners.com>, "Jordan, Bret" <bret.jordan@bluecoat.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>, Terry MacDonald <terry@soltra.com>
Subject:
Re: [cti-cybox] CybOX 3.0: File Object Refactoring

e.g. (maybe not applicable use case):
I am uploading a nicepic.jpg file to a website via an upload form accepting only the extension .jpg
But, I renamed webshell.php to picture.jpg just before uploading

My .php pretended to be a .jpg


2015-12-15 19:41 GMT+03:00 Wunder, John A. <jwunder@mitre.org>:
  • Are there any other issues with the File Object and its subclasses that we’re missing?
  • Does the concept of domain-specific/context-specific extension points make sense?
      · Are there any other default extensions that we should be adding?
      ·
      Are there any other properties for the default extensions that we should be adding?
                                                  Also, we’d like to highlight that we’re still thinking through some of the implications of this approach (how to manage/version/update extensions, etc.), so consider this a living document.

                                                  Regards,
                                                  Ivan and Trey


                                                  ---------------------------------------------------------------------
                                                  To unsubscribe from this mail list, you must leave the OASIS TC that
                                                  generates this mail. Follow this link to all your TCs in OASIS at:

                                                  https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
                                                  [attachment "graycol.gif" deleted by Jason Keirstead/CanEast/IBM]



    ---------------------------------------------------------------------
    To unsubscribe from this mail list, you must leave the OASIS TC that
    generates this mail.  Follow this link to all your TCs in OASIS at:
    https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php 
    [attachment "graycol.gif" deleted by Jason Keirstead/CanEast/IBM] [attachment "C690F973-64C5-4C00-889B-C1A5BB4A2A0B[11].png" deleted by Jason Keirstead/CanEast/IBM]



  • [Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]