OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help

cti-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]

Subject: Re: [cti-comment] Included Packet Object Type into STIX 2.0

Hi Farhan,

We have the ability to record details about a network connection in STIX 2.0 and 2.1, but nothing specifically about a network packet. If you are wanting to send the network packet described in a network connection Object, I would recommend using the Artifact object to embed the network packet itself into.

There are no current plans to add a dedicated Network Packet object. There has been no requests for this at all that I'm aware of in all the time we've been working on STIX 2.x series (circa 2.5 years). We made a conscious decision to only move the objects that were being actively used across from STIX 1.x series to the STIX 2.x series, and unfortunately that didn't make the cut.

The great thing about STIX 2.x, is that you can add your own custom objects and custom extensions if you want for the use cases you have, and only use them in your own environment/trustgroup. So you could create your own Network Packet object if you wanted, but there is unfortunately no guarantee that software processing this will pass through the custom objects. (Maybe that's something we need to fix in STIX 2.1).

Hope that helps.


Terry MacDonald | Chief Product Officer

On Thu, Mar 1, 2018 at 8:01 AM, Farhan Sadique <qclass@protonmail.com> wrote:
Do you have any plans or work in progress to include to network packet object type into STIX 2.x. This was in STIX 1.x

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]