OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-cybox] IP Address Notation (or: I Love CIDR When It's Talking About More Than One IP Address)


I am "OK" with this compromise because it will move the discussion forward...

Still - I just want to reenforce that, this is a data encoding specification. It has nothing at all to do with how analysts have to enter information. Even when analysis make objects "by hand" (for example using the Soltra Edge builder tool or IBM XForce or Threat Transform etc), you are going to be using a tool - "by hand", but via a tool - a tool who can easily encode IPs as CIDRs.

I would assert that if there are indeed threat analysts who routinely craft XML or JSON by hand, I would really like them to give feedback on this thread to affirm that. If there are those who know of this use case first hand, please relay it, and give more details on how their use case proceeds end-to-end - because if hand-crafted JSON is a real use case, then this has important ramifications for how we treat all of the specifications, not just IP addresses.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Paul Patrick ---01/15/2016 07:43:45 PM---I think is a good way forward Sent from my iPhonePaul Patrick ---01/15/2016 07:43:45 PM---I think is a good way forward Sent from my iPhone

From: Paul Patrick <ppatrick@isightpartners.com>
To: Terry MacDonald <terry@soltra.com>
Cc: "Barnum, Sean D." <sbarnum@mitre.org>, "Kirillov, Ivan A." <ikirillov@mitre.org>, "Foley, Alexander - GIS" <alexander.foley@bankofamerica.com>, "Jordan, Bret" <bret.jordan@bluecoat.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Date: 01/15/2016 07:43 PM
Subject: Re: [cti-cybox] IP Address Notation (or: I Love CIDR When It's Talking About More Than One IP Address)
Sent by: <cti-cybox@lists.oasis-open.org>





I think is a good way forward

Sent from my iPhone


On Jan 15, 2016, at 3:44 PM, Terry MacDonald <
terry@soltra.com> wrote:



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]