OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-cybox] CybOX Core Review


Yes but again, in those examples the objects you would want to re-reference would be the ObservedData instances - not he pieces of cybox inside the observed data.

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Jerome Athias ---07/15/2016 12:16:16 PM---UUIDs could not be needed/useful for some objects/values, bJerome Athias ---07/15/2016 12:16:16 PM---UUIDs could not be needed/useful for some objects/values, but could be for others (maybe in future)

From: Jerome Athias <athiasjerome@gmail.com>
To: Jason Keirstead/CanEast/IBM@IBMCA
Cc: "Mates, Jeffrey CIV DC3/DCCI" <Jeffrey.Mates@dc3.mil>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>, "Ivan A. Kirillov" <ikirillov@mitre.org>, Terry MacDonald <terry.macdonald@cosive.com>
Date: 07/15/2016 12:16 PM
Subject: Re: [cti-cybox] CybOX Core Review
Sent by: <cti-cybox@lists.oasis-open.org>





UUIDs could not be needed/useful for some objects/values, but could be for others (maybe in future)
The same PLC ID value in 2 versions of a malware, or the same ROP Chain or Gadget in two Exploits (if one day we get there) would be 'complex' objects and not just values where UUIDs would be good to have. (Which, also, even if not ideal, could help for CTI 'obfuscation')

On Friday, 15 July 2016, Jason Keirstead <
Jason.Keirstead@ca.ibm.com> wrote:


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]