[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [cti] RE: [Non-DoD Source] [cti] Another STIX 2.1 Extension example
Thatâs a fair point. I have to admit my main concern with it is if we see products adding extension objects in each package instead of persisting them that weâll run into a scenario where we need to both maintain long-term stores of extension GUIDs for to resolve internal mappings and read through and update these when each package is parsed. That feels messier to me than just being able to directly reference a URL, but I also understand the desire to be able to provide versioning for this within STIX. The trouble I run into when thinking about it is that the ID mappings a system will need to persist to handle both types of resolutions may end up forcing redownloading of the schema each time it shows up with the possibility that the same URL would be used for each in which case it would end up still missing out on the precise definition. The use of an object instead of just pointing to a URL that follows the major / minor / patch versioning scheme makes more sense to me when we inject content to the top level of an object since the extension_properties provide a really useful mechanism to explain these. I might just not be thinking about this enough though. //SIGNED// Jeffrey Mates, Civ DC3/TSD Computer Scientist Technical Solutions Development jeffrey.mates@dc3.mil 410-694-4335 From: Bret Jordan <bret.jordan@broadcom.com> All active links contained in this email were disabled. Please verify the identity of the sender, and confirm the authenticity of all links contained within the message prior to copying and pasting the address to a Web browser. The thing I like about the nested extension under a UUID is that if you do not know about the extension it is super easy to just capture the data as JSON.Raw data and store it. Putting values at the top-level means you have to parse the data first and pull everything out that you know how to use, then loop back through to see if there is anything else and then try and figure out if you can do anything with it. I find that to be much more problematic. Thanks, Bret PGP Fingerprint: 63B4 FC53 680A 6B7D 1447 F2C0 74F8 ACAE 7415 0050 "Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." On Mon, Oct 19, 2020 at 3:12 PM Mates, Jeffrey CIV DC3/TSD <Jeffrey.Mates@dc3.mil < Caution-mailto:Jeffrey.Mates@dc3.mil > > wrote:
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]