OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-cybox] Network flow object suggestions


I am unsure how you would encode a DDOS using sighting in this manner without duplicating the network connection, can you give an example?

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Terry MacDonald ---08/26/2016 04:18:57 PM---Which is what the multiplicity in the STIX sighting relatTerry MacDonald ---08/26/2016 04:18:57 PM---Which is what the multiplicity in the STIX sighting relationship object is for. We should keep the n

From: Terry MacDonald <terry.macdonald@cosive.com>
To: Jason Keirstead/CanEast/IBM@IBMCA
Cc: cti-cybox@lists.oasis-open.org, Bret Jordan <bret.jordan@bluecoat.com>
Date: 08/26/2016 04:18 PM
Subject: Re: [cti-cybox] Network flow object suggestions
Sent by: <cti-cybox@lists.oasis-open.org>





Which is what the multiplicity in the STIX sighting relationship object is for. We should keep the network flow object for recording one flow, and use the sighting for saying 'and other stuff like this'.

Cheers
Terry MacDonald
Cosive


On 26/08/2016 22:13, "Jason Keirstead" <Jason.Keirstead@ca.ibm.com> wrote:






[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]