OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [cti-cybox] Re: CybOX 3.0: HashType Refactoring


I think the hashing algorithms should be either a controlled vocabulary or a type enum like Jerome suggested, that is part of the specification. Anything that a coder would implement as an Enumeration, should be a controlled vocabulary or an enumeration.

RE:


The reason you need this is not because you see it being extended, it is so that everyone agrees on how it should be entered into the document so that it can be parsed properly and efficiently. "MD5" vs "md5", "sha" vs "SHA-1" vs "sha256" vs "SHA-256"

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for "Davidson II, Mark S" ---2015/11/03 08:43:46 AM---My comment is really about controlled vocabularies "Davidson II, Mark S" ---2015/11/03 08:43:46 AM---My comment is really about controlled vocabularies in general. I tend to have a gut reaction of want

From: "Davidson II, Mark S" <mdavidson@mitre.org>
To: "Kirillov, Ivan A." <ikirillov@mitre.org>, Jason Keirstead/CanEast/IBM@IBMCA, John Anderson <janderson@soltra.com>
Cc: "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Date: 2015/11/03 08:43 AM
Subject: RE: [cti-cybox] Re: CybOX 3.0: HashType Refactoring




My comment is really about controlled vocabularies in general. I tend to have a gut reaction of wanting to do away with controlled vocabularies wherever we have them because they are hard for me to implement. That said, I think changing two key factors about controlled vocabularies would change the way I feel about them.

I think we should consider improving controlled vocabularies in these two areas:
If controlled vocabularies were to meet the requirements I lay out above, I would have no opinion on whether hashes use a default vocabulary or not. As controlled vocabularies currently stand, my preference is for not using them.

Thank you.
-Mark



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]