OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-users message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-users] Towards a better understanding of JSON-LD (Was: MTI Binding)


I'll echo this and add onto it as well, the other much larger consideration here is simply the realities of software development. Every new format that exists in the wild, is therefore another format that you need to add support for to your tools if you want to have a workable ecosystem where tools can talk to each-other. It's also another format that needs to be developed, tested, and certified, against all of those various other tools, both internally and externally.

It doesn't matter if there are pre-existing translation libraries available for this translation. Libraries like that only reduce a tiny amount of the overall workload. The marshalling and de-marshalling of data is only one piece of the work effort... arguably, its the smaller piece.

In fact, with every new wire format, the integration work required will increase in a geometric fashion.

This is why it is so important to have "one true" wire format codified as a standard.

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com
Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Jordan, Bret" ---2015/10/07 12:58:58 PM---Yes, for professional modelers and people that work in RDF"Jordan, Bret" ---2015/10/07 12:58:58 PM---Yes, for professional modelers and people that work in RDF every day, this would seem like the best

From: "Jordan, Bret" <bret.jordan@bluecoat.com>
To: Cory Casanave <cory-c@modeldriven.com>
Cc: Shawn Riley <shawn.p.riley@gmail.com>, "cti-users@lists.oasis-open.org" <cti-users@lists.oasis-open.org>
Date: 2015/10/07 12:58 PM
Subject: Re: [cti-users] Towards a better understanding of JSON-LD (Was: MTI Binding)
Sent by: <cti-users@lists.oasis-open.org>





Yes, for professional modelers and people that work in RDF every day, this would seem like the best thing to do. You are using advanced tools, software packages and libraries that can consume anything as long as it is RDF.

The problem is, most of the developers that we need to recruit to write tools and software to work with STIX are not professional modelers and RDF people. They work in PHP and _javascript_, or in Objective-C, Android-Java, C++, Python, Perl, Ruby etc. They need to read in a blob of data over the wire, say JSON. Stick that in to memory somewhere. Then unmarshal that in to a struct or series of maps/dictionaries and then do something with it.

Further, most vendors that build security products or networking products use a PHP interface or Java interface with a ton of JSON and a REST API. Lets not make things hard for them. We need to recruit them. We need to get them on board.

Speaking from my past experience in start-ups. If the technology is outside of the development stack, and it is a checkbox feature, then it will never get done. We need this to be so simple and easy that everyone says "why would I NOT do this, lets just do it make it happen". At RSA and Blackhat I talked with a lot of startups that said, "if you would only do JSON we could adopt this". I talked with Facebook and they said if we could do JSON, they could support it natively in their solution.

If we want to win, lets make it easy for organizations to understand and use.

Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."
[attachment "signature.asc" deleted by Jason Keirstead/CanEast/IBM]




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]