OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-cybox message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-cybox] CybOX Object Selection


Sorry it seems like I am harping on such a minor point - I just really don't get the use case for the object...

The last thing I want to be responsible for when I publish a network flow object, is to do a bunch of APNIC lookups to fill in fields like "Name" and "RIR" in an AS object, when all of this can be looked up at receipt time by anyone who wants to know it.... this is a similar conversation as what we had with the "vulnerability" object, where I think we got consensus to drop all the superfluous fields that can be looked up like "name" etc.

Are people planning on supplying actual intel *about* an AS? Is there a concrete use of this in the field today...

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Jason Keirstead---02/03/2016 06:57:09 PM---I don't really get the use case still. Why would you need Jason Keirstead---02/03/2016 06:57:09 PM---I don't really get the use case still. Why would you need to make a relationship to an integer?

From: Jason Keirstead/CanEast/IBM@IBMCA
To: "Kirillov, Ivan A." <ikirillov@mitre.org>
Cc: "Paul Patrick" <ppatrick@isightpartners.com>, "Trey Darley" <trey@soltra.com>, cti-cybox@lists.oasis-open.org
Date: 02/03/2016 06:57 PM
Subject: Re: [cti-cybox] CybOX Object Selection
Sent by: <cti-cybox@lists.oasis-open.org>





I don't really get the use case still.

Why would you need to make a relationship to an integer?

It would always be more efficient to just store the duplicate integer everywhere.

Sent from IBM Verse


Kirillov, Ivan A. --- Re: [cti-cybox] CybOX Object Selection ---

From:"Kirillov, Ivan A." <ikirillov@mitre.org>
To:"Paul Patrick" <ppatrick@isightpartners.com>, "Jason Keirstead" <Jason.Keirstead@ca.ibm.com>
Cc:"Trey Darley" <trey@soltra.com>, cti-cybox@lists.oasis-open.org
Date:Wed, Feb 3, 2016 3:33 PM
Subject:Re: [cti-cybox] CybOX Object Selection


Ah, yup – that’s another valid use case. Thanks for the input Paul.

Regards,
Ivan

From: Paul Patrick <ppatrick@isightpartners.com>
Date:
Wednesday, February 3, 2016 at 12:28 PM
To:
Ivan Kirillov <ikirillov@mitre.org>, Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Cc:
Trey Darley <trey@soltra.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Subject:
Re: [cti-cybox] CybOX Object Selection

Ivan,

In addition, having it as a separate object helps in the ability to relate it to other things (at least that is how we use it)


Paul

From: <cti-cybox@lists.oasis-open.org> on behalf of Ivan Kirillov <ikirillov@mitre.org>
Date:
Wednesday, February 3, 2016 at 1:21 PM
To:
Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Cc:
Trey Darley <trey@soltra.com>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Subject:
Re: [cti-cybox] CybOX Object Selection





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]